Malicious PowerPoint Documents Abusing Mouse Over Actions
A new type of malicious MS Office document has appeared: a PowerPoint document that executes a PowerShell command by hovering over a link with the mouse cursor (this attack does not involve VBA macros…
Last week a new exploitation technique for PHP applications was announced at the BlackHat USA conference. Find out everything you need to know in this blog post.SummaryThe security researcher Sam Thom…
CVE-2018-9411: New critical vulnerability in multiple high-privileged Android services | Zimperium M…
As part of our platform research in Zimperium zLabs, I have recently disclosed a critical vulnerability affecting multiple high-privileged Android services to Google. Google designated it as CVE-2018-…
tl;dr There was a remote code execution vulnerability on packagist.org, the default package server behind Composer, a PHP package manager. Packagist currentl...
DEFCON 17: Stealing Profits from Spammers or: How I learned to Stop Worrying and Love the Spam
Speaker: Grant Jordan WiseCrack Tools Every time you look at your inbox, there it is... SPAM! Your penis needs enlargement, a horny single girl from Russia "...
Атака на Github Pages с перехватом сайта на вашем домене
Большинство разработчиков знают и любят github pages. На случай, если вы не встречались с ними — этот сервис даёт возможность создать статический сайт из...
With $20 of Gear from Amazon, Nearly Anyone Can Make This IMSI-Catcher in 30 Minutes
Surveillance takes on different character when it trickles down to more ordinary, everyday users. The significance and threat from IMSI-catchers is multiplied when a lot more people can deploy one usi…
An anti-sandbox/anti-reversing trick using the GetClipboardOwner API
This is a little nifty trick for detecting virtualization environments. At least, some of them. Anytime you restore the snapshot of your virtual machine your guest OS environment will usually run some…
The shortage of proficient cyber operators in a world now dependent on connectivity and information has left nations scrambling to build capabilities in a vo...
Cymulate’s research team has discovered a way to abuse the Online Video feature on Microsoft Word to execute malicious code. Attackers could use this for malicious purposes such as phishing, as the do…