Staffing Is Top SOC Challenge Even as AI Proliferates, Says SANS
SANS Institute study finds few SOCs have built AI into defined workflows, despite widespread adoption
SANS Institute study finds few SOCs have built AI into defined workflows, despite widespread adoption
Your playbooks move fast, but GreyNoise helps them move smarter. Here are five ways GreyNoise drives better decisions in SOAR.
Join us for our 90 minute Sumer of CCNA session, today at 5PM ET!
A previously Linux-focused backdoor attributed to Chinese threat actors now has Windows variants, expanding its operational reach across multiple platforms. The updated SprySOCKS malware supports over 30 command-and-control commands, enabling attackers to execute diverse post-compromise objectives while maintaining stealth on infected systems.
The Rokarolla Android trojan combines banking credential theft with extensive device surveillance capabilities, allowing attackers to monitor victims beyond financial fraud. The malware actively suppresses fraud alerts that would normally warn users of unauthorized account activity, enabling prolonged exploitation of compromised banking credentials.
ISSA study finds most security professionals feel challenged by colleagues’ involvement in cyber
DragonForce ransomware operators leveraged Microsoft Teams to conceal their command and control communications during an attack on a major organization, exploiting a Teams visitor token to evade detection. By disguising malicious activity as legitimate Teams traffic, the attackers were able to obscure their presence from security defenses monitoring network communications.
ESET researchers have identified SprySOCKS for Windows, an upgraded backdoor in FishMonger's toolkit that leverages a kernel driver to achieve enhanced stealth capabilities. The use of kernel-level access represents a significant evolution in the malware's evasion techniques, making detection and removal more challenging for traditional security tools.
Have you ever wondered how you can look at the USN Journal on a live and running system? In this episode, we'll dive in to see how it actually works and whether it matches what we’ve been taught. *** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. *** 📖 Chapters 00:00 - Intro 01:04 - Demo 🛠 Resources NTFS Journal Forensics:
A newly discovered phishing kit called EvilTokens exploits Microsoft's legitimate authentication mechanisms to compromise accounts while bypassing traditional password theft and fake login page detection. The attack manipulates the authentication flow itself, allowing attackers to gain access without needing to intercept credentials or deploy convincing counterfeit login interfaces.
00:00 - Introduction 01:00 - Start of nmap 02:10 - Finding some CVE's in FontTools, but doing more recon on the site before we dive too deep 06:30 - Enumerating the website is flask based upon error message (cookie works too) 09:20 - Trying to create an error message which could leak information about the server like its local path 11:30 - Taking a look at portal.variatype.htb which shows it is PHP 13:50 - Gobuster found a .git, running git-dumper to get the source 15:30 - Finding a File Disclosure in the PHP App because the ../ removal was not recursive 20:30 - Updating the FontTools script to put a reverse shell in, then using it to upload a php reverse shell to the portal 22:00 - Reverse shell returned 22:30 - Looking at the sudoers file, we can't read it but the metadata is a treasure trove of information. Looking at timestamps, doing some filtering getting nothing 26:30 - Using docker to spin up a debian image quickly, looking at the size of the default sudoers file and then comparing it to the box to see it has likely been modified 28:00 - Using find to look for files owned by steve, finding a backup script. It uses FontForge which has a CVE. We can put a malicious archive file and get RCE 37:00 - Shell returned as Steve 39:00 - Looking at the validator python script, first thought with symlinks won't work because we don't own the plugin directory 41:30 - Finding a CVE within SetupTools, using it to write an SSH Key
Three posts? In three days? Are we insane? We're home alone, there's no one to stop us, and we're up past bedtime. So, we need to talk about Splunk. On June 10th, Splunk published this CVE-2026-20253 advisory: It has everything that we
Researchers discovered hundreds of "short-sleeve" RSA and DSA keys with biased bit patterns that could be quickly factored using a novel polynomial-based cryptanalytic technique. The vulnerability, traced to a type mismatch bug in CompleteFTP versions 10.0.0–12.0.0 (RSA) and 10.0.0–23.0.4 (DSA), affected 603 unique RSA keys and 74 DSA keys; EnterpriseDT has released detection and remediation tools for affected users. The research highlights how structural weaknesses in cryptographic implementations can enable practical attacks and underscores the importance of using standard cryptographic libraries rather
Learn how SentinelOne empowers modern enterprises to safely adopt Claude with Prompt Security, AI SIEM, and Wayfinder Frontier AI.
It is yet another day in this parallel universe of security, where the devices we bolt onto the edge of our networks to keep the bad people out are, with remarkable consistency, the exact thing that let the bad people in. While we’ve seemingly had a breather from
Sensor Intel Series: June 2026 CVE Trends
A shift in operational pattern of the infamous Vietnam-aligned APT group
A company that's expecting a cyberattack but hasn’t actively prepared for it risks making the hardest decisions at the worst possible moment
Today, Ivanti published an advisory. “No way?” we hear you say. "Yes way!" Today’s advisory outlines two vulnerabilities in Ivanti’s Sentry product, appealing directly to our inner desire for sophisticated server-side, pre-authenticated vulnerabilities. CVE-2026-10520 An OS Command Injection