Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026

NetworkChuck·0 views · 2 months ago

Join us for our 90 minute Sumer of CCNA session, today at 5PM ET!

MalwareInfosecurity Magazine·2 months ago

SprySOCKS Backdoor Expands From Linux to Windows

A previously Linux-focused backdoor attributed to Chinese threat actors now has Windows variants, expanding its operational reach across multiple platforms. The updated SprySOCKS malware supports over 30 command-and-control commands, enabling attackers to execute diverse post-compromise objectives while maintaining stealth on infected systems.

MalwareInfosecurity Magazine·2 months ago

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

The Rokarolla Android trojan combines banking credential theft with extensive device surveillance capabilities, allowing attackers to monitor victims beyond financial fraud. The malware actively suppresses fraud alerts that would normally warn users of unauthorized account activity, enabling prolonged exploitation of compromised banking credentials.

RansomwareInfosecurity Magazine·2 months ago

DragonForce Ransomware Exploited Microsoft Teams to Hide in Attack Against Major Company

DragonForce ransomware operators leveraged Microsoft Teams to conceal their command and control communications during an attack on a major organization, exploiting a Teams visitor token to evade detection. By disguising malicious activity as legitimate Teams traffic, the attackers were able to obscure their presence from security defenses monitoring network communications.

MalwareWeLiveSecurity·2 months ago

FishMonger’s arsenal upgraded: SprySOCKS for Windows

ESET researchers have identified SprySOCKS for Windows, an upgraded backdoor in FishMonger's toolkit that leverages a kernel driver to achieve enhanced stealth capabilities. The use of kernel-level access represents a significant evolution in the malware's evasion techniques, making detection and removal more challenging for traditional security tools.

I was wrong about VPNs

NetworkChuck·216K views · 2 months ago

How the USN Journal Really Works

13Cubed·2.2K views · 2 months ago

Have you ever wondered how you can look at the USN Journal on a live and running system? In this episode, we'll dive in to see how it actually works and whether it matches what we’ve been taught. *** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. *** 📖 Chapters 00:00 - Intro 01:04 - Demo 🛠 Resources NTFS Journal Forensics:

PhishingWeLiveSecurity·2 months ago

EvilTokens: A phishing attack that doesn’t steal your password

A newly discovered phishing kit called EvilTokens exploits Microsoft's legitimate authentication mechanisms to compromise accounts while bypassing traditional password theft and fake login page detection. The attack manipulates the authentication flow itself, allowing attackers to gain access without needing to intercept credentials or deploy convincing counterfeit login interfaces.

HackTheBox - VariaType

IppSec·5.9K views · 2 months ago

00:00 - Introduction 01:00 - Start of nmap 02:10 - Finding some CVE's in FontTools, but doing more recon on the site before we dive too deep 06:30 - Enumerating the website is flask based upon error message (cookie works too) 09:20 - Trying to create an error message which could leak information about the server like its local path 11:30 - Taking a look at portal.variatype.htb which shows it is PHP 13:50 - Gobuster found a .git, running git-dumper to get the source 15:30 - Finding a File Disclosure in the PHP App because the ../ removal was not recursive 20:30 - Updating the FontTools script to put a reverse shell in, then using it to upload a php reverse shell to the portal 22:00 - Reverse shell returned 22:30 - Looking at the sudoers file, we can't read it but the metadata is a treasure trove of information. Looking at timestamps, doing some filtering getting nothing 26:30 - Using docker to spin up a debian image quickly, looking at the size of the default sudoers file and then comparing it to the box to see it has likely been modified 28:00 - Using find to look for files owned by steve, finding a backup script. It uses FontForge which has a CVE. We can put a malicious archive file and get RCE 37:00 - Shell returned as Steve 39:00 - Looking at the validator python script, first thought with symlinks won't work because we don't own the plugin directory 41:30 - Finding a CVE within SetupTools, using it to write an SSH Key

VulnerabilityTrail of Bits·2 months ago

Factoring "short-sleeve" RSA keys with polynomials

Researchers discovered hundreds of "short-sleeve" RSA and DSA keys with biased bit patterns that could be quickly factored using a novel polynomial-based cryptanalytic technique. The vulnerability, traced to a type mismatch bug in CompleteFTP versions 10.0.0–12.0.0 (RSA) and 10.0.0–23.0.4 (DSA), affected 603 unique RSA keys and 74 DSA keys; EnterpriseDT has released detection and remediation tools for affected users. The research highlights how structural weaknesses in cryptographic implementations can enable practical attacks and underscores the importance of using standard cryptographic libraries rather

Load more