Date Author Title

OT HAPPY THANKSGIVING DAY CANADA

2010-10-11Adrien de BeaupreOT: Happy Thanksgiving Day Canada

OT

2024-11-06/a>Jesse La Grew[Guest Diary] Insights from August Web Traffic Surge
2024-10-09/a>Xavier MertensFrom Perfctl to InfoStealer
2024-09-13/a>Jesse La GrewFinding Honeypot Data Clusters Using DBSCAN: Part 2
2024-09-06/a>Jesse La GrewEnrichment Data: Keeping it Fresh
2024-08-16/a>Jesse La Grew[Guest Diary] 7 minutes and 4 steps to a quick win: A write-up on custom tools
2024-07-10/a>Jesse La GrewFinding Honeypot Data Clusters Using DBSCAN: Part 1
2024-06-17/a>Xavier MertensNew NetSupport Campaign Delivered Through MSIX Packages
2024-06-07/a>Johannes UllrichFinding End of Support Dates: UK PTSI Regulation
2024-04-25/a>Jesse La GrewDoes it matter if iptables isn't running on my honeypot?
2024-04-17/a>Xavier MertensMalicious PDF File Used As Delivery Mechanism
2024-04-15/a>Johannes UllrichQuick Palo Alto Networks Global Protect Vulnerablity Update (CVE-2024-3400)
2024-04-13/a>Johannes UllrichCritical Palo Alto GlobalProtect Vulnerability Exploited (CVE-2024-3400)
2024-03-10/a>Guy BruneauWhat happens when you accidentally leak your AWS API keys? [Guest Diary]
2024-03-07/a>Jesse La Grew[Guest Diary] AWS Deployment Risks - Configuration and Credential File Targeting
2024-03-03/a>Guy BruneauCapturing DShield Packets with a LAN Tap [Guest Diary]
2024-02-28/a>Johannes UllrichExploit Attempts for Unknown Password Reset Vulnerability
2024-02-25/a>Guy BruneauUtilizing the VirusTotal API to Query Files Uploaded to DShield Honeypot [Guest Diary]
2024-02-18/a>Guy BruneauMirai-Mirai On The Wall... [Guest Diary]
2024-02-15/a>Jesse La Grew[Guest Diary] Learning by doing: Iterative adventures in troubleshooting
2024-02-03/a>Guy BruneauDShield Sensor Log Collection with Elasticsearch
2024-01-30/a>Johannes UllrichWhat did I say to make you stop talking to me?
2024-01-17/a>Jesse La GrewNumber Usage in Passwords
2024-01-07/a>Guy BruneauSuspicious Prometei Botnet Activity
2023-12-27/a>Guy BruneauUnveiling the Mirai: Insights into Recent DShield Honeypot Activity [Guest Diary]
2023-12-13/a>Guy BruneauT-shooting Terraform for DShield Honeypot in Azure [Guest Diary]
2023-12-10/a>Guy BruneauHoneypots: From the Skeptical Beginner to the Tactical Enthusiast
2023-11-30/a>John BambenekProphetic Post by Intern on CVE-2023-1389 Foreshadows Mirai Botnet Expansion Today
2023-11-27/a>Guy BruneauDecoding the Patterns: Analyzing DShield Honeypot Activity [Guest Diary]
2023-11-22/a>Guy BruneauCVE-2023-1389: A New Means to Expand Botnets
2023-11-20/a>Jesse La GrewOverflowing Web Honeypot Logs
2023-11-09/a>Guy BruneauRouters Targeted for Gafgyt Botnet [Guest Diary]
2023-10-15/a>Guy BruneauDomain Name Used as Password Captured by DShield Sensor
2023-09-18/a>Johannes UllrichInternet Wide Multi VPN Search From Single /24 Network
2023-09-14/a>Jesse La GrewDShield and qemu Sitting in a Tree: L-O-G-G-I-N-G
2023-09-09/a>Guy Bruneau?Anyone get the ASN of the Truck that Hit Me?!?: Creating a PowerShell Function to Make 3rd Party API Calls for Extending Honeypot Information [Guest Diary]
2023-09-05/a>Jesse La GrewCommon usernames submitted to honeypots
2023-09-02/a>Jesse La GrewWhat is the origin of passwords submitted to honeypots?
2023-08-31/a>Guy BruneauPotential Weaponizing of Honeypot Logs [Guest Diary]
2023-08-21/a>Xavier MertensQuick Malware Triage With Inotify Tools
2023-08-12/a>Guy BruneauDShield Sensor Monitoring with a Docker ELK Stack [Guest Diary]
2023-07-23/a>Guy BruneauInstall & Configure Filebeat on Raspberry Pi ARM64 to Parse DShield Sensor Logs
2023-07-13/a>Jesse La GrewDShield Honeypot Maintenance and Data Retention
2023-07-06/a>Jesse La GrewIDS Comparisons with DShield Honeypot Data
2023-06-22/a>Brad DuncanQakbot (Qbot) activity, obama271 distribution tag
2023-06-11/a>Guy BruneauDShield Honeypot Activity for May 2023
2023-05-22/a>Johannes UllrichProbes for recent ABUS Security Camera Vulnerability: Attackers keep an eye on everything.
2023-05-14/a>Guy BruneauDShield Sensor Update
2023-05-09/a>Russ McReeExploratory Data Analysis with CISSM Cyber Attacks Database - Part 2
2023-04-17/a>Jan KoprivaThe strange case of Great honeypot of China
2023-04-12/a>Brad DuncanRecent IcedID (Bokbot) activity
2023-03-11/a>Xavier MertensOverview of a Mirai Payload Generator
2023-03-02/a>Didier StevensYARA: Detect The Unexpected ...
2023-02-28/a>Brad DuncanBB17 distribution Qakbot (Qbot) activity
2023-02-24/a>Brad DuncanURL files and WebDAV used for IcedID (Bokbot) infection
2023-02-09/a>Xavier MertensA Backdoor with Smart Screenshot Capability
2023-02-07/a>Yee Ching TokA Survey of Bluetooth Vulnerabilities Trends (2023 Edition)
2023-02-05/a>Didier StevensVideo: Analyzing Malicious OneNote Documents
2023-02-01/a>Didier StevensDetecting (Malicious) OneNote Files
2023-01-31/a>Jesse La GrewDShield Honeypot Setup with pfSense
2023-01-25/a>Xavier MertensA First Malicious OneNote Document
2023-01-05/a>Brad DuncanMore Brazil malspam pushing Astaroth (Guildma) in January 2023
2022-12-29/a>Jesse La GrewOpening the Door for a Knock: Creating a Custom DShield Listener
2022-12-21/a>Guy BruneauDShield Sensor Setup in Azure
2022-12-20/a>Xavier MertensLinux File System Monitoring & Actions
2022-12-02/a>Brad Duncanobama224 distribution Qakbot tries .vhd (virtual hard disk) images
2022-11-02/a>Brad DuncanWho put the "Dark" in DarkVNC?
2022-10-16/a>Didier StevensVideo: Analysis of a Malicious HTML File (QBot)
2022-10-13/a>Didier StevensAnalysis of a Malicious HTML File (QBot)
2022-10-07/a>Xavier MertensCritical Fortinet Vulnerability Ahead
2022-09-18/a>Didier StevensVideo: Grep & Tail -f With Notepad++
2022-09-12/a>Johannes UllrichVirusTotal Result Comparisons for Honeypot Malware
2022-09-05/a>Didier StevensQuickie: Grep & Tail -f With Notepad++
2022-08-30/a>Johannes UllrichTwo things that will never die: bash scripts and IRC!
2022-08-24/a>Brad DuncanMonster Libra (TA551/Shathak) --> IcedID (Bokbot) --> Cobalt Strike & DarkVNC
2022-08-19/a>Brad DuncanBrazil malspam pushes Astaroth (Guildma) malware
2022-08-18/a>Johannes UllrichHoneypot Attack Summaries with Python
2022-08-12/a>Brad DuncanMonster Libra (TA551/Shathak) pushes IcedID (Bokbot) with Dark VNC and Cobalt Strike
2022-07-27/a>Brad DuncanIcedID (Bokbot) with Dark VNC and Cobalt Strike
2022-07-10/a>Guy BruneauExcel 4 Emotet Maldoc Analysis using CyberChef
2022-07-07/a>Brad DuncanEmotet infection with Cobalt Strike
2022-07-05/a>Jan KoprivaEternalBlue 5 years after WannaCry and NotPetya
2022-06-30/a>Brad DuncanCase Study: Cobalt Strike Server Lives on After Its Domain Is Suspended
2022-06-28/a>Johannes UllrichPossible Scans for HiByMusic Devices
2022-06-24/a>Xavier MertensPython (ab)using The Windows GUI
2022-06-15/a>Johannes UllrichTerraforming Honeypots. Installing DShield Sensors in the Cloud
2022-06-09/a>Brad DuncanTA570 Qakbot (Qbot) tries CVE-2022-30190 (Follina) exploit (ms-msdt)
2022-05-30/a>Xavier MertensNew Microsoft Office Attack Vector via "ms-msdt" Protocol Scheme (CVE-2022-30190)
2022-05-19/a>Brad DuncanBumblebee Malware from TransferXL URLs
2022-05-12/a>Rob VandenBrinkWhen Get-WebRequest Fails You
2022-05-03/a>Johannes UllrichSome Honeypot Updates
2022-04-20/a>Brad Duncan"aa" distribution Qakbot (Qbot) infection with DarkVNC traffic
2022-04-19/a>Johannes UllrichResetting Linux Passwords with U-Boot Bootloaders
2022-03-31/a>Johannes UllrichSpring Vulnerability Update - Exploitation Attempts CVE-2022-22965
2022-03-25/a>Xavier MertensXLSB Files: Because Binary is Stealthier Than XML
2022-03-16/a>Brad DuncanQakbot infection with Cobalt Strike and VNC activity
2022-03-10/a>Xavier MertensCredentials Leaks on VirusTotal
2022-03-03/a>Johannes UllrichAttackers Search For Exposed "LuCI" Folders: Help me understand this attack
2022-03-02/a>Johannes UllrichThe More Often Something is Repeated, the More True It Becomes: Dealing with Social Media
2022-02-16/a>Brad DuncanAstaroth (Guildma) infection
2022-02-15/a>Xavier MertensWho Are Those Bots?
2022-02-09/a>Brad DuncanExample of Cobalt Strike from Emotet infection
2022-01-25/a>Brad DuncanEmotet Stops Using 0.0.0.0 in Spambot Traffic
2022-01-19/a>Brad Duncan0.0.0.0 in Emotet Spambot Traffic
2022-01-07/a>Xavier MertensCustom Python RAT Builder
2021-12-28/a>Russ McReeLotL Classifier tests for shells, exfil, and miners
2021-12-22/a>Brad DuncanDecember 2021 Forensic Contest: Answers and Analysis
2021-12-16/a>Brad DuncanHow the "Contact Forms" campaign tricks people
2021-12-02/a>Brad DuncanTA551 (Shathak) pushes IcedID (Bokbot)
2021-11-26/a>Guy BruneauSearching for Exposed ASUS Routers Vulnerable to CVE-2021-20090
2021-11-20/a>Guy BruneauHikvision Security Cameras Potentially Exposed to Remote Code Execution
2021-11-16/a>Brad DuncanEmotet Returns
2021-11-04/a>Brad DuncanOctober 2021 Forensic Contest: Answers and Analysis
2021-11-04/a>Tom WebbXmount for Disk Images
2021-11-01/a>Yee Ching TokRevisiting BrakTooth: Two Months Later
2021-10-20/a>Xavier MertensThanks to COVID-19, New Types of Documents are Lost in The Wild
2021-10-04/a>Johannes UllrichBoutique "Dark" Botnet Hunting for Crumbs
2021-09-23/a>Xavier MertensExcel Recipe: Some VBA Code with a Touch of Excel4 Macro
2021-08-31/a>Yee Ching TokBrakTooth: Impacts, Implications and Next Steps
2021-08-13/a>Brad DuncanExample of Danabot distributed through malspam
2021-07-24/a>Bojan ZdrnjaActive Directory Certificate Services (ADCS - PKI) domain admin vulnerability
2021-07-24/a>Xavier MertensAgent.Tesla Dropped via a .daa Image and Talking to Telegram
2021-06-30/a>Brad DuncanJune 2021 Forensic Contest: Answers and Analysis
2021-06-24/a>Xavier MertensDo you Like Cookies? Some are for sale!
2021-05-14/a>Xavier Mertens"Open" Access to Industrial Systems Interface is Also Far From Zero
2021-04-15/a>Johannes UllrichWhy and How You Should be Using an Internal Certificate Authority
2021-04-06/a>Jan KoprivaMalspam with Lokibot vs. Outlook and RFCs
2021-04-02/a>Xavier MertensC2 Activity: Sandboxes or Real Victims?
2021-03-06/a>Xavier MertensSpotting the Red Team on VirusTotal!
2021-03-03/a>Brad DuncanQakbot infection with Cobalt Strike
2021-02-28/a>Didier StevensMaldocs: Protection Passwords
2021-02-23/a>Jan KoprivaQakbot in a response to Full Disclosure post
2021-02-22/a>Didier StevensUnprotecting Malicious Documents For Inspection
2021-02-17/a>Brad DuncanMalspam pushing Trickbot gtag rob13
2021-02-13/a>Guy BruneauvSphere Replication updates address a command injection vulnerability (CVE-2021-21976) - https://www.vmware.com/security/advisories/VMSA-2021-0001.html
2021-01-28/a>Daniel WesemannEmotet vs. Windows Attack Surface Reduction
2021-01-26/a>Brad DuncanTA551 (Shathak) Word docs push Qakbot (Qbot)
2021-01-20/a>Brad DuncanQakbot activity resumes after holiday break
2021-01-15/a>Guy BruneauObfuscated DNS Queries
2020-12-09/a>Brad DuncanRecent Qakbot (Qbot) activity
2020-12-04/a>Guy BruneauDetecting Actors Activity with Threat Intel
2020-11-18/a>Xavier MertensWhen Security Controls Lead to Security Issues
2020-11-03/a>Brad DuncanEmotet -> Qakbot -> more Emotet
2020-10-23/a>Russ McReeSooty: SOC Analyst's All-in-One Tool
2020-10-20/a>Xavier MertensMirai-alike Python Scanner
2020-10-14/a>Brad DuncanMore TA551 (Shathak) Word docs push IcedID (Bokbot)
2020-09-29/a>Xavier MertensManaging Remote Access for Partners & Contractors
2020-08-24/a>Xavier MertensTracking A Malware Campaign Through VT
2020-08-22/a>Guy BruneauRemote Desktop (TCP/3389) and Telnet (TCP/23), What might they have in Common?
2020-08-19/a>Xavier MertensExample of Word Document Delivering Qakbot
2020-08-03/a>Xavier MertensPowershell Bot with Multiple C2 Protocols
2020-08-01/a>Jan KoprivaWhat pages do bad bots look for?
2020-07-15/a>Brad DuncanWord docs with macros for IcedID (Bokbot)
2020-07-01/a>Jim ClausingSetting up the Dshield honeypot and tcp-honeypot.py
2020-06-28/a>Guy Bruneautcp-honeypot.py Logstash Parser & Dashboard Update
2020-06-25/a>Johannes UllrichTech Tuesday Recap / Recordings: Part 2 (Installing the Honeypot) release.
2020-06-20/a>Tom WebbPi Zero HoneyPot
2020-06-13/a>Guy BruneauMirai Botnet Activity
2020-06-05/a>Johannes UllrichCyber Security for Protests
2020-06-05/a>Remco VerhoefNot so FastCGI!
2020-05-20/a>Brad DuncanMicrosoft Word document with malicious macro pushes IcedID (Bokbot)
2020-05-06/a>Xavier MertensKeeping an Eye on Malicious Files Life Time
2020-05-01/a>Jim ClausingAttack traffic on TCP port 9673
2020-04-20/a>Didier StevensKPOT AutoIt Script: Analysis
2020-04-12/a>Didier StevensReader Analysis: "Dynamic analysis technique to get decrypted KPOT Malware."
2020-04-02/a>Tom WebbTPOT's Cowrie to ISC Logs
2020-04-01/a>Brad DuncanQakbot malspam sent from an infected Windows host
2020-03-23/a>Didier StevensKPOT Deployed via AutoIt Script
2020-03-22/a>Didier StevensMore COVID-19 Themed Malware
2020-03-21/a>Guy BruneauHoneypot - Scanning and Targeting Devices & Services
2020-03-18/a>Brad DuncanTrickbot gtag red5 distributed as a DLL file
2020-01-28/a>Brad DuncanEmotet epoch 1 infection with Trickbot gtag mor84
2020-01-23/a>Xavier MertensComplex Obfuscation VS Simple Trick
2020-01-12/a>Guy BruneauELK Dashboard and Logstash parser for tcp-honeypot Logs
2019-12-24/a>Brad DuncanMalspam with links to Word docs pushes IcedID (Bokbot)
2019-12-18/a>Brad DuncanEmotet infection with spambot activity
2019-12-15/a>Didier StevensVirusTotal Email Submissions
2019-12-11/a>Brad DuncanGerman language malspam pushes yet another wave of Trickbot
2019-11-13/a>Brad DuncanAn example of malspam pushing Lokibot malware, November 2019
2019-11-03/a>Didier StevensYou Too? "Unusual Activity with Double Base64 Encoding"
2019-10-30/a>Xavier MertensKeep an Eye on Remote Access to Mailboxes
2019-10-02/a>Brad DuncanA recent example of Emotet malspam
2019-09-24/a>Xavier MertensHuge Amount of remotewebaccess.com Sites Found in Certificate Transparency Logs
2019-09-18/a>Brad DuncanEmotet malspam is back
2019-09-03/a>Johannes Ullrich[Guest Diary] Tricky LNK points to TrickBot
2019-08-14/a>Brad DuncanRecent example of MedusaHTTP malware
2019-08-08/a>Johannes Ullrich[Guest Diary] The good, the bad and the non-functional, or "how not to do an attack campaign"
2019-07-26/a>Kevin ShorttDVRIP Port 34567 - Uptick
2019-06-28/a>Rob VandenBrinkVerifying Running Processes against VirusTotal - Domain-Wide
2019-05-16/a>Xavier MertensThe Risk of Authenticated Vulnerability Scans
2019-03-13/a>Brad DuncanMalspam pushes Emotet with Qakbot as the follow-up malware
2019-03-06/a>Brad DuncanMalspam with password-protected word docs still pushing IcedID (Bokbot) with Trickbot
2019-02-14/a>Xavier MertensOld H-Worm Delivered Through GitHub
2019-01-16/a>Brad DuncanEmotet infections and follow-up malware
2019-01-10/a>Brad DuncanHeartbreaking Emails: "Love You" Malspam
2019-01-09/a>Russ McReegganimate: Animate YouR Security Analysis
2018-12-23/a>Guy BruneauScanning Activity, end Goal is to add Hosts to Mirai Botnet
2018-12-18/a>Brad DuncanMalspam links to password-protected Word docs that push IcedID (Bokbot)
2018-12-05/a>Brad DuncanCampaign evolution: Hancitor changes its Word macros
2018-12-04/a>Brad DuncanMalspam pushing Lokibot malware
2018-11-15/a>Brad DuncanEmotet infection with IcedID banking Trojan
2018-11-14/a>Brad DuncanDay in the life of a researcher: Finding a wave of Trickbot malspam
2018-11-09/a>Tom WebbPlaying with T-POT
2018-09-26/a>Brad DuncanOne Emotet infection leads to three follow-up malware infections
2018-07-26/a>Xavier MertensWindows Batch File Deobfuscation
2018-07-24/a>Brad DuncanRecent Emotet activity
2018-06-27/a>Renato MarinhoSilently Profiling Unknown Malware Samples
2018-06-16/a>Russ McReeAnomaly Detection & Threat Hunting with Anomalize
2018-06-13/a>Remco VerhoefFrom Microtik with Love
2018-05-27/a>Guy BruneauCapture and Analysis of User Agents
2018-05-19/a>Xavier MertensMalicious Powershell Targeting UK Bank Customers
2018-05-09/a>Xavier MertensNice Phishing Sample Delivering Trickbot
2018-03-08/a>Xavier MertensCRIMEB4NK IRC Bot
2017-11-30/a>Brad DuncanMore Malspam pushing Emotet malware
2017-11-28/a>Xavier MertensApple High Sierra Uses a Passwordless Root Account
2017-11-25/a>Guy BruneauExim Remote Code Exploit
2017-11-11/a>Xavier MertensKeep An Eye on your Root Certificates
2017-10-19/a>Brad DuncanHSBC-themed malspam uses ISO attachments to push Loki Bot malware
2017-08-15/a>Brad DuncanMalspam pushing Trickbot banking Trojan
2017-08-10/a>Didier StevensMaldoc Analysis with ViperMonkey
2017-08-03/a>Johannes UllrichUsing a Raspberry Pi honeypot to contribute data to DShield/ISC
2017-07-28/a>Didier StevensStatic Analysis of Emotet Maldoc
2017-07-27/a>Xavier MertensTinyPot, My Small Honeypot
2017-07-26/a>Brad DuncanMalspam pushing Emotet malware
2017-07-19/a>Xavier MertensBots Searching for Keys & Config Files
2017-06-28/a>Brad DuncanPetya? I hardly know ya! - an ISC update on the 2017-06-27 ransomware outbreak
2017-05-08/a>Renato MarinhoExploring a P2P Transient Botnet - From Discovery to Enumeration
2017-03-12/a>Guy BruneauHoneypot Logs and Tracking a VBE Script
2017-02-21/a>Jim ClausingQuick and dirty generic listener
2017-02-10/a>Brad DuncanHancitor/Pony malspam
2017-01-10/a>Johannes UllrichPort 37777 "MapTable" Requests
2017-01-07/a>Xavier MertensUsing Security Tools to Compromize a Network
2017-01-06/a>John BambenekGreat Misadventures of Security Vendors: Absurd Sandboxing Edition
2016-12-31/a>Xavier MertensOngoing Scans Below the Radar
2016-12-07/a>Xavier MertensThe Passwords You Should Never Use
2016-11-13/a>Guy BruneauBitcoin Miner File Upload via FTP
2016-09-15/a>Xavier MertensIn Need of a OTP Manager Soon?
2016-09-10/a>Xavier MertensOngoing IMAP Scan, Anyone Else?
2016-08-22/a>Russ McReeRed Team Tools Updates: hashcat and SpiderFoot
2016-07-27/a>Xavier MertensAnalyze of a Linux botnet client source code
2016-07-07/a>Johannes UllrichPatchwork: Is it still "Advanced" if all you have to do is Copy/Paste?
2016-06-15/a>Richard PorterWarp Speed Ahead, L7 Open Source Packet Generator: Warp17
2016-06-03/a>Tom ListonMySQL is YourSQL
2016-05-14/a>Guy BruneauINetSim as a Basic Honeypot
2016-04-27/a>Tom WebbKippos Cousin Cowrie
2016-03-15/a>Xavier MertensDockerized DShield SSH Honeypot
2016-03-13/a>Xavier MertensSSH Honeypots (Ab)used as Proxy
2016-02-26/a>Xavier MertensQuick Audit of *NIX Systems
2016-01-31/a>Guy BruneauWindows 10 and System Protection for DATA Default is OFF
2016-01-23/a>Didier StevensSigcheck and VirusTotal for Offline Machine
2016-01-08/a>Mark HofmanSLOTH, attack on TLS using MD5
2015-10-12/a>Guy BruneauCritical Vulnerability in Multiple Cisco Products - Apache Struts 2 Command Execution http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131023-struts2
2015-08-06/a>Didier StevensSigcheck and virustotal-search
2015-07-21/a>Didier StevensSearching Through the VirusTotal Database
2015-07-17/a>Didier StevensProcess Explorer and VirusTotal
2015-07-17/a>Didier StevensSigcheck and VirusTotal
2015-07-17/a>Didier StevensAutoruns and VirusTotal
2015-04-14/a>Johannes UllrichOdd POST Request To Web Honeypot
2015-04-08/a>Tom WebbIs it a breach or not?
2015-03-16/a>Johannes UllrichAutomatically Documenting Network Connections From New Devices Connected to Home Networks
2015-03-02/a>Johannes UllrichHow Do You Control the Internet of Things Inside Your Network?
2015-02-12/a>Johannes UllrichDid You Remove That Debug Code? Netatmo Weather Station Sending WPA Passphrase in the Clear
2015-02-06/a>Johannes UllrichAnthem, TurboTax and How Things "Fit Together" Sometimes
2014-10-09/a>Johannes UllrichCSAM: My servers started speaking IRC, and that is when I started to listen!
2014-10-03/a>Johannes UllrichCSAM: The Power of Virustotal to Turn Harmless Binaries Malicious
2014-08-16/a>Lenny ZeltserWeb Server Attack Investigation - Installing a Bot and Reverse Shell via a PHP Vulnerability
2014-07-31/a>Chris MohanA Honeypot for home: Raspberry Pi
2014-07-30/a>Rick WannerSymantec Endpoint Protection Privilege Escalation Zero Day
2014-07-28/a>Johannes UllrichInteresting HTTP User Agent "chroot-apach0day"
2014-07-14/a>Johannes UllrichThe Internet of Things: How do you "on-board" devices?
2014-06-30/a>Johannes UllrichShould I setup a Honeypot? [SANSFIRE]
2014-06-28/a>Mark HofmanNo more Microsoft advisory email notifications?
2014-06-04/a>Richard Porterp0f, Got Packets?
2014-05-01/a>Johannes UllrichBusybox Honeypot Fingerprinting and a new DVR scanner
2014-03-04/a>Daniel WesemannTriple Handshake Cookie Cutter
2014-02-07/a>Rob VandenBrinkHello Virustotal? It's Microsoft Calling.
2014-01-16/a>Kevin ShorttPort 4028 - Interesting Activity
2013-12-07/a>Guy BruneauSuspected Active Rovnix Botnet Controller
2013-11-22/a>Rick WannerPort 0 DDOS
2013-11-02/a>Rick WannerProtecting Your Family's Computers
2013-10-26/a>Guy BruneauActive Perl/Shellbot Trojan
2013-10-05/a>Richard PorterAdobe Breach Notification, Notifications?
2013-09-18/a>Rob VandenBrinkCisco DCNM Update Released
2013-09-02/a>Adrien de Beaupre[OT] Happy Labo(u)r Day USA and Canada!
2013-08-13/a>Swa FrantzenMicrosoft security advisories: RDP and MD5 deprecation in Microsoft root certificates
2013-08-11/a>Bojan ZdrnjaXATattacks (attacks on xat.com)
2013-08-09/a>Kevin ShorttCopy Machines - Changing Scanned Content
2013-07-25/a>Johannes UllrichA Couple of SSH Brute Force Compromises
2013-07-13/a>Lenny ZeltserDecoy Personas for Safeguarding Online Identity Using Deception
2013-05-19/a>Kevin ShorttPort 51616 - Got Packets?
2013-04-14/a>Johannes UllrichProtocol 61 Packets Follow Up
2013-04-04/a>Johannes UllrichMicrosoft April Patch Tuesday Advance Notification
2013-03-29/a>Chris MohanDoes your breach email notification look like a phish?
2013-03-09/a>Guy BruneauIPv6 Focus Month: IPv6 Encapsulation - Protocol 41
2013-03-02/a>Scott FendleyEvernote Security Issue
2013-02-21/a>Bojan ZdrnjaSSHD rootkit in the wild
2013-02-16/a>Lorna HutchesonFedora RedHat Vulnerabilty Released
2013-01-15/a>Russ McReeCisco introducing Cisco Security Notices 16 JAN 2013
2013-01-09/a>Rob VandenBrinkHotmail seeing some temporary access issues
2013-01-08/a>Richard PorterA picture worth a 1000 barcodes?
2012-12-06/a>Johannes UllrichHow to identify if you are behind a "Transparent Proxy"
2012-10-26/a>Russ McReeCyber Security Awareness Month - Day 26 - Attackers use trusted domain to propagate Citadel Zeus variant
2012-08-22/a>Adrien de BeaupreApple Remote Desktop update fixes no encryption issue
2012-07-12/a>Rob VandenBrinkToday at SANSFIRE - Dude Your Car is PWND !
2012-07-05/a>Adrien de BeaupreMicrosoft advanced notification for July 2012 patch Tuesday
2012-05-22/a>Johannes UllrichThe "Do Not Track" header
2012-05-22/a>Johannes UllrichWhen factors collapse and two factor authentication becomes one.
2012-04-26/a>Richard PorterDefine Irony: A medical device with a Virus?
2012-03-16/a>Russ McReeMS12-020 RDP vulnerabilities: Patch, Mitigate, Detect
2012-02-28/a>Russ McReeQOTD from securityburnout.org
2012-02-27/a>Johannes UllrichOdd Vanishing Signatures in OS X XProtect
2011-12-08/a>Adrien de BeaupreMicrosoft Security Bulletin Advance Notification for December 2011
2011-12-06/a>Pedro BuenoThe RedRet connection...
2011-11-28/a>Tom ListonA Puzzlement...
2011-11-22/a>Pedro BuenoUpdates on ZeroAccess and BlackHole front...
2011-11-19/a>Pedro BuenoDragon Research Group (DRG) announced the white paper entitled "VNC: Threats and Countermeasures" : https://dragonresearchgroup.org/insight/vnc-tac.html
2011-10-26/a>Rob VandenBrinkThe Theoretical "SSL Renegotiation" Issue gets a Whole Lot More Real !
2011-10-01/a>Mark HofmanAdobe Photoshop for Windows Vulnerability (CVE-2011-2443)
2011-09-20/a>Swa FrantzenDiginotar declared bankrupt
2011-09-19/a>Guy BruneauMS Security Advisory Update - Fraudulent DigiNotar Certificates
2011-09-15/a>Swa FrantzenDigiNotar looses their accreditation for qualified certificates
2011-09-13/a>Swa FrantzenMore DigiNotar intermediate certificates blocklisted at Microsoft
2011-09-07/a>Lenny ZeltserGlobalSign Temporarily Stops Issuing Certificates to Investigate a Potential Breach
2011-09-06/a>Swa FrantzenDigiNotar audit - intermediate report available
2011-09-06/a>Johannes UllrichMicrosoft Releases Diginotar Related Patch and Advisory
2011-09-01/a>Swa FrantzenDigiNotar breach - the story so far
2011-08-31/a>Johannes UllrichFirefox/Thunderbird 6.0.1 released to blocklist bad DigiNotar SSL certificates
2011-08-11/a>Guy BruneauBlackBerry Enterprise Server Critical Update
2011-08-04/a>Johannes UllrichIRC traffic on non standard ports
2011-07-29/a>Richard PorterApple Lion talking on TCP 5223
2011-07-02/a>Pedro BuenoBootkits, they are back at full speed...
2011-06-21/a>Chris MohanStartSSL, a web authentication authority, suspend services after a security breach
2011-06-08/a>Johannes UllrichSpam from compromised Hotmail accounts
2011-05-14/a>Guy BruneauWebsense Study Claims Canada Next Hotbed for Cybercrime Web Hosting Activity
2011-04-28/a>Chris MohanDSL Reports advise 9,000 accounts were compromised
2011-04-28/a>Chris MohanGathering and use of location information fears - or is it all a bit too late
2011-04-20/a>Daniel WesemannVirustotal.com hiccup
2011-04-03/a>Richard PorterExtreme Disclosure? Not yet but a great trend!
2011-02-28/a>Deborah HalePossible Botnet Scanning
2011-02-14/a>Richard PorterAnonymous Damage Control Anybody?
2011-01-12/a>Richard PorterHow Many Loyalty Cards do you Carry?
2011-01-12/a>Richard PorterHas Big Brother gone Global?
2011-01-11/a>Kevin ShorttSpam Cannons on Holiday
2011-01-10/a>Manuel Humberto Santander PelaezVirusTotal VTzilla firefox/chrome plugin
2010-12-19/a>Raul SilesIntel's new processors have a remote kill switch (Anti-Theft 3.0)
2010-11-18/a>Chris CarboniStopping the ZeroAccess Rootkit
2010-11-18/a>Chris CarboniAll of your pages are belonging to us
2010-11-05/a>Adrien de BeaupreBot honeypot
2010-11-01/a>Manuel Humberto Santander PelaezCheckpoint UTM-1 edge VPN boxes worldwide did an unscheduled reboot
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Access – Are things getting too easy, or too hard?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - VPN and Remote Access Tools
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote Access Tools
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Tunnels - to Split or not to Split?
2010-10-11/a>Adrien de BeaupreOT: Happy Thanksgiving Day Canada
2010-10-04/a>Mark HofmanOnline Voting
2010-10-03/a>Adrien de BeaupreH went down.
2010-08-19/a>Daniel WesemannCasper the unfriendly ghost
2010-07-29/a>Rob VandenBrinkFBI, Slovenian and Spanish Police announce more arrests of Mariposa Botnet Creator, Operators
2010-07-21/a>Adrien de BeaupreAdobe Reader Protected Mode
2010-07-21/a>Adrien de BeaupreDell PowerEdge R410 replacement motherboard firmware contains malware
2010-06-15/a>Manuel Humberto Santander PelaezMastercard delivering cards with OTP device included
2010-06-14/a>Manuel Humberto Santander PelaezNew way of social engineering on IRC
2010-05-12/a>Rob VandenBrinkAdobe Shockwave Update
2010-05-07/a>Johannes UllrichStock market "wipe out" may be due to computer error
2010-05-02/a>Mari NicholsZbot Social Engineering
2010-04-23/a>Adrien de BeaupreShadowserver botnet rules
2010-03-25/a>Kevin ListonZeus wants to do your taxes
2010-03-15/a>Adrien de BeaupreSpamassassin Milter Plugin Remote Root Attack
2010-03-11/a>donald smithCert write up on Skype IMBot Logic and Functionality.
2010-03-10/a>Rob VandenBrinkMicrosoft Security Advisory 981374 - Remote Code Execution Vulnerability for IE6 and IE7
2010-03-10/a>Rob VandenBrinkMicrosoft re-release of KB973811 - attacks on Extended Protection for Authentication
2010-02-19/a>Mark HofmanMS10-015 may cause Windows XP to blue screen (but only if you have malware on it)
2010-02-09/a>Adrien de BeaupreWhen is a 0day not a 0day? Samba symlink bad default config
2010-02-02/a>Johannes UllrichPushdo Update
2010-02-02/a>Guy BruneauCisco Secure Desktop Remote XSS Vulnerability
2010-02-01/a>Rob VandenBrinkNMAP 5.21 - Is UDP Protocol Specific Scanning Important? Why Should I Care?
2010-01-25/a>William Salusky"Bots and Spiders and Crawlers, be gone!" - or - "New Open Source WebAppSec tools, Huzzah!"
2009-12-21/a>Marcus SachsiPhone Botnet Analysis
2009-12-07/a>Rob VandenBrinkLayer 2 Network Protections – reloaded!
2009-11-14/a>Adrien de BeaupreMicrosoft advisory for Windows 7 / Windows Server 2008 R2 Remote SMB DoS Exploit released
2009-11-13/a>Deborah HalePushdo/Cutwail Spambot - A Little Known BIG Problem
2009-11-13/a>Adrien de BeaupreTLS & SSLv3 renegotiation vulnerability explained
2009-11-12/a>Rob VandenBrinkWindows 7 / Windows Server 2008 Remote SMB Exploit
2009-11-11/a>Rob VandenBrinkLayer 2 Network Protections against Man in the Middle Attacks
2009-11-08/a>Kevin ListonFireEye takes on Ozdok and Recovery Ideas
2009-11-05/a>Swa FrantzenTLS Man-in-the-middle on renegotiation vulnerability made public
2009-11-05/a>Swa FrantzenRIM fixes random code execution vulnerability
2009-10-30/a>Rob VandenBrinkNew version of NIST 800-41, Firewalls and Firewall Policy Guidelines
2009-10-26/a>Johannes UllrichWeb honeypot Update
2009-10-10/a>Tony CarothersUser Notification for Possible Infected Systems
2009-10-06/a>Adrien de BeaupreCyber Security Awareness Month - Day 6 ports 67&68 udp - bootp and dhcp
2009-10-05/a>Adrien de BeaupreTime to change your hotmail/gmail/yahoo password
2009-09-18/a>Jason LamResults from Webhoneypot project
2009-09-16/a>Raul SilesIETF Draft for Remediation of Bots in ISP Networks
2009-09-07/a>Jim ClausingRequest for packets
2009-08-29/a>Guy BruneauImmunet Protect - Cloud and Community Malware Protection
2009-08-18/a>Deborah HaleSecurity Bulletin for ColdFusion and JRun
2009-07-23/a>John BambenekMissouri Passes Breach Notification Law: Gap Still Exists for Banking Account Information
2009-06-27/a>Tony CarothersNew NIAP Strategy on the Horizon
2009-06-11/a>Jason LamDshield Web Honeypot going beta
2009-05-07/a>Deborah HaleBotnet hijacking reveals 70GB of stolen data
2009-04-24/a>John BambenekData Leak Prevention: Proactive Security Requirements of Breach Notification Laws
2009-03-26/a>Mark HofmanWebhoneypot fun
2009-02-17/a>Jason LamDShield Web Honeypot - Alpha Preview Release
2008-12-01/a>Jason LamCall for volunteers - Web Honeypot Project
2008-11-05/a>donald smithBot net hunters get an improved tool from SRI bothunters
2008-11-05/a>donald smithhacking the election
2008-09-09/a>Swa FrantzenThe complaint that's an attack
2008-09-01/a>John BambenekThe Number of Machines Controlled by Botnets Has Jumped 4x in Last 3 Months
2008-08-16/a>Marcus SachsAnother Infected Digital Photo Frame
2008-07-22/a>Mari Nichols‘Cold Boot’ Attack Utility Tools
2008-07-19/a>William SaluskyA twist in fluxnet operations. Enter Hydraflux
2008-07-15/a>Maarten Van HorenbeeckBot controller mimicry
2008-05-25/a>Stephen HallCisco's Response to Rootkit presentation
2008-05-23/a>Mike PoorCisco IOS Rootkit thoughts
2008-05-06/a>Marcus SachsIndustrial Control Systems Vulnerability
2008-04-08/a>Swa FrantzenNotes file viewer vulnerabilities
2008-04-07/a>John BambenekGot Kraken?
2008-04-07/a>John BambenekKraken Technical Details: UPDATED x3
2008-03-13/a>Jason LamRemote File Include spoof!?
2006-11-20/a>Joel EslerMS06-070 Remote Exploit
2006-08-31/a>Swa FrantzenNT botnet submitted
2006-08-31/a>Joel EslerMS06-040 Worm

HAPPY

2013-03-25/a>Johannes UllrichIPv6 Focus Month: IPv6 over IPv4 Preference
2010-10-11/a>Adrien de BeaupreOT: Happy Thanksgiving Day Canada

THANKSGIVING

2010-10-11/a>Adrien de BeaupreOT: Happy Thanksgiving Day Canada

DAY

2024-07-09/a>Johannes UllrichMicrosoft Patch Tuesday July 2024
2024-06-11/a>Johannes UllrichMicrosoft Patch Tuesday June 2024
2024-03-12/a>Johannes UllrichMicrosoft Patch Tuesday - March 2024
2024-03-05/a>Johannes UllrichApple Releases iOS/iPadOS Updates with Zero Day Fixes.
2024-01-22/a>Johannes UllrichApple Updates Everything - New 0 Day in WebKit
2023-12-12/a>Johannes UllrichMicrosoft Patch Tuesday December 2023
2023-10-10/a>Johannes UllrichOctober 2023 Microsoft Patch Tuesday Summary
2023-09-07/a>Johannes UllrichApple Releases iOS/iPadOS 16.6.1, macOS 13.5.2, watchOS 9.6.2 fixing two zeroday vulnerabilities
2023-06-22/a>Johannes UllrichApple Patches Exploited Vulnerabilities in iOS/iPadOS, macOS, watchOS and Safari
2023-05-16/a>Jesse La GrewSignals Defense With Faraday Bags & Flipper Zero
2023-04-07/a>Johannes UllrichApple Patching Two 0-Day Vulnerabilities in iOS and macOS
2023-02-14/a>Johannes UllrichMicrosoft February 2023 Patch Tuesday
2022-11-29/a>Johannes UllrichPacket Tuesday Episode 3: TCP Urgent Flag. https://packettuesday.com
2022-08-17/a>Johannes UllrichApple Patches Two Exploited Vulnerabilities
2022-05-10/a>Renato MarinhoMicrosoft May 2022 Patch Tuesday
2022-05-03/a>Rob VandenBrinkFinding the Real "Last Patched" Day (Interim Version)
2022-02-10/a>Johannes UllrichiOS/iPadOS and MacOS Update: Single WebKit 0-Day Vulnerability Patched
2022-01-11/a>Johannes UllrichMicrosoft Patch Tuesday - January 2022
2021-11-27/a>Didier StevensVideo: SANS Holiday Hack Challenge 2021 Q&A with Ed Skoudis
2021-09-14/a>Renato MarinhoMicrosoft September 2021 Patch Tuesday
2021-04-13/a>Richard PorterMicrosoft April 2021 Patch Tuesday
2021-03-03/a>Johannes UllrichMicrosoft Releases Exchange Emergency Patch to Fix Actively Exploited Vulnerability
2020-12-08/a>Johannes UllrichDecember 2020 Microsoft Patch Tuesday: Exchange, Sharepoint, Dynamics and DNS Spoofing
2020-06-18/a>Jan KoprivaBroken phishing accidentally exploiting Outlook zero-day
2020-05-14/a>Rob VandenBrinkPatch Tuesday Revisited - CVE-2020-1048 isn't as "Medium" as MS Would Have You Believe
2020-05-01/a>Jim ClausingAttack traffic on TCP port 9673
2020-03-23/a>Didier StevensWindows Zeroday Actively Exploited: Type 1 Font Parsing Remote Code Execution Vulnerability
2020-03-10/a>Johannes UllrichMicrosoft Patch Tuesday March 2020
2019-07-09/a>John BambenekMSFT July 2019 Patch Tuesday
2019-04-25/a>Rob VandenBrinkUnpatched Vulnerability Alert - WebLogic Zero Day
2018-12-11/a>Richard PorterMicrosoft December 2018 Patch Tuesday
2018-10-09/a>Johannes UllrichOctober 2018 Microsoft Patch Tuesday
2018-09-11/a>Johannes UllrichMicrosoft September Patch Tuesday Summary
2018-06-12/a>Johannes UllrichMicrosoft June 2018 Patch Tuesday
2018-02-01/a>Johannes UllrichAdobe Flash 0-Day Used Against South Korean Targets
2017-07-11/a>Renato MarinhoJuly's Microsoft Patch Tuesday
2017-05-02/a>Richard PorterDo you have Intel AMT? Then you have a problem today! Intel Active Management Technology INTEL-SA-00075
2017-03-14/a>Johannes UllrichFebruary and March Microsoft Patch Tuesday
2017-02-14/a>Johannes UllrichMicrosoft Patch Tuesday Delayed
2017-02-04/a>Xavier MertensDetecting Undisclosed Vulnerabilities with Security Tools & Features
2017-01-10/a>Johannes UllrichJanuary 2017 Microsoft Patch Tuesday
2016-09-13/a>Rob VandenBrinkMicrosoft Patch Tuesday Analysis
2016-08-25/a>Xavier MertensOut-of-Band iOS Patch Fixes 0-Day Vulnerabilities
2016-07-12/a>Johannes UllrichMicrosoft Patch Tuesday Summary for July 2016
2016-05-12/a>Xavier MertensAdobe Released Updates to Fix Critical Vulnerability
2016-04-06/a>Bojan ZdrnjaYAFP (Yet Another Flash Patch)
2016-02-09/a>Johannes UllrichMicrosoft February 2016 Patch Tuesday
2016-02-09/a>Johannes UllrichAdobe Patch Tuesday - February 2016
2016-01-12/a>Alex StanfordJanuary 2016 Microsoft Patch Tuesday
2015-12-08/a>Johannes UllrichDecember 2015 Microsoft Patch Tuesday
2015-11-10/a>Johannes UllrichNovember 2015 Microsoft Patch Tuesday
2015-10-13/a>Alex StanfordOctober 2015 Microsoft Patch Tuesday
2015-09-08/a>Johannes UllrichSeptember 2015 Microsoft Patch Tuesday
2015-08-11/a>Manuel Humberto Santander PelaezAugust 2015 Microsoft Patch Tuesday
2015-07-27/a>Daniel WesemannAngler's best friends
2015-07-14/a>Johannes UllrichJuly 2015 Microsoft Patch Tuesday
2015-07-12/a>Rick WannerAnother Adobe Flash Zero Day http://www.kb.cert.org/vuls/id/338736
2015-06-09/a>Johannes UllrichMicrosoft Patch Tuesday Summary for June 2015
2015-05-12/a>Johannes UllrichMay 2015 Microsoft Patch Tuesday Summary
2015-04-14/a>Alex StanfordMicrosoft Patch Tuesday - April 2015
2015-03-10/a>Johannes UllrichMicrosoft March Patch Tuesday
2015-02-10/a>Mark BaggettMicrosoft Update Advisory for February 2015
2015-02-05/a>Johannes UllrichAdobe Flash Player Update Released, Fixing CVE 2015-0313
2015-01-23/a>Adrien de BeaupreInfocon change to yellow for Adobe Flash issues
2015-01-13/a>Johannes UllrichMicrosoft Patch Tuesday - January 2015 (Really? Telnet?)
2014-12-09/a>Alex StanfordMicrosoft Patch Tuesday - December 2014
2014-11-18/a>Jim ClausingMicrosoft November out-of-cycle patch MS14-068
2014-11-11/a>Johannes UllrichMicrosoft November 2014 Patch Tuesday
2014-10-14/a>Johannes UllrichMicrosoft October 2014 Patch Tuesday
2014-09-09/a>Alex StanfordMicrosoft Patch Tuesday - September 2014
2014-08-12/a>Alex StanfordMicrosoft Patch Tuesday - August 2014
2014-07-30/a>Rick WannerSymantec Endpoint Protection Privilege Escalation Zero Day
2014-07-28/a>Johannes UllrichInteresting HTTP User Agent "chroot-apach0day"
2014-07-08/a>Alex StanfordMicrosoft Patch Tuesday - July
2014-06-10/a>Alex StanfordMicrosoft Patch Tuesday June 2014
2014-06-06/a>Johannes UllrichMicrosoft June Patch Tuesday Advance Notification
2014-05-21/a>John BambenekNew, Unpatched IE 0 Day published at ZDI
2014-05-13/a>Johannes UllrichMicrosoft May 2014 Patch Tuesday
2014-05-01/a>Johannes UllrichMicrosoft Announces Special Patch for IE 0-day (Win XP included!)
2014-04-08/a>Richard PorterApril 2014 Microsoft Patches
2014-03-24/a>Johannes UllrichNew Microsoft Advisory: Unpatched Word Flaw used in Targeted Attacks
2014-03-11/a>Johannes UllrichMicrosoft Patch Tuesday March 2014
2014-03-08/a>Guy BruneauMicrosoft March Patch Pre-Announcement
2014-02-20/a>Stephen HallAbobe out of band patch announcement (APSB14-07)
2014-02-14/a>Chris MohanFireEye reports IE 10 zero-day being used in watering hole attack
2014-02-11/a>Johannes UllrichFebruary 2014 Microsoft Patch Tuesday
2014-02-07/a>Johannes UllrichMicrosoft Advance Notification for February 2014
2014-01-14/a>Johannes UllrichMicrosoft Patch Tuesday January 2014
2013-12-10/a>Johannes UllrichMicrosoft December Patch Tuesday
2013-12-07/a>Guy BruneauMicrosoft December Patch Pre-Announcement
2013-11-28/a>Rob VandenBrinkMicrosoft Security Advisory (2914486): Vulnerability in Microsoft Windows Kernel 0 day exploit in wild
2013-11-12/a>Johannes UllrichNovember 2013 Microsoft Patch Tuesday
2013-11-09/a>Guy BruneauIE Zero-Day Vulnerability Exploiting msvcrt.dll
2013-10-08/a>Johannes UllrichMicrosoft October 2013 Patch Tuesday
2013-09-10/a>Swa FrantzenAdobe September 2013 Black Tuesday Overview
2013-09-10/a>Swa FrantzenMicrosoft September 2013 Black Tuesday Overview
2013-08-28/a>Bojan ZdrnjaMS13-056 (false positive)? alerts
2013-08-13/a>Swa FrantzenMicrosoft August 2013 Black Tuesday Overview
2013-08-13/a>Swa FrantzenMicrosoft security advisories: RDP and MD5 deprecation in Microsoft root certificates
2013-07-09/a>Swa FrantzenMicrosoft July 2013 Black Tuesday Overview
2013-07-09/a>Swa FrantzenAdobe July 2013 Black Tuesday Overview
2013-07-06/a>Guy BruneauMicrosoft July Patch Pre-Announcement
2013-06-11/a>Swa FrantzenMicrosoft June 2013 Black Tuesday Overview
2013-06-11/a>Swa FrantzenAdobe June 2013 Black Tuesday Overview
2013-06-11/a>Swa FrantzenOther Microsoft Black Tuesday News
2013-06-11/a>Swa Frantzenvmware security advisory VMSA-2013-0008
2013-05-14/a>Swa FrantzenMicrosoft May 2013 Black Tuesday Overview
2013-05-14/a>Swa FrantzenFirefox & Thunderbird released
2013-05-14/a>Swa FrantzenAdobe May 2013 Black Tuesday Overview
2013-05-14/a>Swa FrantzenMicrosoft Security Advisory 2846338
2013-05-09/a>John BambenekAdobe Releases 0-day Security Advisory for Coldfusion, Exploit Code Available. Advisory here: http://www.adobe.com/support/security/advisories/apsa13-03.html
2013-05-04/a>Kevin ShorttThe Zero-Day Pendulum Swings
2013-04-09/a>Swa FrantzenMicrosoft April 2013 Black Tuesday Overview
2013-04-09/a>Swa FrantzenAdobe April 2013 Black Tuesday Overview
2013-04-04/a>Johannes UllrichMicrosoft April Patch Tuesday Advance Notification
2013-03-12/a>Swa FrantzenMicrosoft March 2013 Black Tuesday Overview
2013-03-12/a>Swa FrantzenAdobe March 2013 Black Tueday
2013-02-14/a>Adam SwangerISC Monthly Threat Update - February 2013 http://isc.sans.edu/podcastdetail.html?id=3121
2013-02-12/a>Adam SwangerMicrosoft February 2013 Black Tuesday Update - Overview
2013-02-12/a>Swa FrantzenAdobe Feb 2013 Black Tuesday patches
2013-02-08/a>Johannes UllrichMicrosoft February Patch Tuesday Advance Notification
2013-02-07/a>John BambenekAdobe Releases Patches for 0-day Vulnerability in Flash Player for Windows and Mac, Upgrade now: http://www.adobe.com/support/security/bulletins/apsb13-04.html
2013-01-22/a>Richard PorterUsing Metasploit for Patch Sanity Checks
2013-01-14/a>Richard PorterMicrosoft Out of Cycle Patch: IE http://technet.microsoft.com/en-us/security/bulletin/ms13-jan
2013-01-14/a>Richard PorterJanuary 2013 Microsoft Out of Cycle Patch
2013-01-13/a>Stephen HallJava 0-Day patched as Java 7 U 11 released
2013-01-12/a>Stephen HallJava 0-day impact to Java 6 (and beyond?)
2013-01-10/a>Adam SwangerISC Monthly Threat Update New Format
2013-01-08/a>Richard PorterMicrosoft January 2013 Black Tuesday Update - Overview
2013-01-04/a>Daniel WesemannPatch pre-notification from Adobe and Microsoft
2013-01-02/a>Russ McReeEMET 3.5: The Value of Looking Through an Attacker's Eyes
2012-12-11/a>John BambenekMicrosoft December 2012 Black Tuesday Update - Overview
2012-11-26/a>John BambenekOnline Shopping for the Holidays? Tips, News and a Fair Warning
2012-11-13/a>Jim ClausingMicrosoft November 2012 Black Tuesday Update - Overview
2012-10-09/a>Johannes UllrichMicrosoft October 2012 Black Tuesday Update - Overview
2012-10-04/a>Johannes UllrichMicrosoft October Patch Pre-Announcement
2012-09-17/a>Rob VandenBrinkIE Zero Day is "For Real"
2012-09-11/a>Adam SwangerMicrosoft September 2012 Black Tuesday Update - Overview
2012-09-01/a>Russ McReeBlackhole targeting Java vulnerability via fake Microsoft Services Agreement email phish
2012-08-14/a>Rick WannerMicrosoft August 2012 Black Tuesday Update - Overview
2012-08-04/a>Kevin ListonVendors: More Patch-Release Options Please
2012-07-10/a>Swa FrantzenMicrosoft July 2012 Black Tuesday Update - Overview
2012-07-10/a>Swa FrantzenMicrosoft revoking trust in Microsoft certificates - SA 2728973
2012-07-10/a>Swa FrantzenMicrosoft fix-it to disable gadgets - SA 2719662
2012-07-05/a>Adrien de BeaupreMicrosoft advanced notification for July 2012 patch Tuesday
2012-06-12/a>Swa FrantzenAdobe June 2012 Black Tuesday patches
2012-06-12/a>Swa FrantzenMicrosoft June 2012 Black Tuesday Update - Overview
2012-06-12/a>Swa FrantzenJava 7u5 and 6u33 released
2012-06-01/a>Johannes UllrichWhat Does "IPv6 Day" mean to you?
2012-05-23/a>Mark BaggettProblems with MS12-035 affecting XP, SBS and Windows 2003?
2012-05-08/a>Adam SwangerMicrosoft May 2012 Black Tuesday Update - Overview
2012-04-15/a>Rick Wanner.Net update affects printing from some applications
2012-04-10/a>Swa FrantzenMicrosoft April 2012 Black Tuesday Update - Overview
2012-04-10/a>Swa FrantzenAdobe April 2012 Black Tuesday Update
2012-04-06/a>Johannes UllrichMicrosoft April Patch Tuesday Pre-Announcement (6 Patches): http://technet.microsoft.com/en-us/security/bulletin/ms12-apr
2012-03-13/a>Lenny ZeltserMarch 2012 Microsoft Black Tuesday
2012-02-14/a>Johannes UllrichFebruary 2012 Microsoft Black Tuesday
2012-01-10/a>Adrien de BeaupreJanuary 2012 Microsoft Black Tuesday Summary
2012-01-10/a>Adrien de BeaupreAdobe January 2012 Black Tuesday overview
2012-01-06/a>Guy BruneauJanuary 2012 Patch Tuesday Pre-release
2011-12-29/a>Richard PorterASP.Net Vulnerability
2011-12-25/a>Deborah HaleMerry Christmas, Happy Holidays
2011-12-21/a>Chris MohanThe off switch
2011-12-13/a>Johannes UllrichDecember 2011 Microsoft Black Tuesday Summary
2011-12-08/a>Adrien de BeaupreNewest Adobe Flash 11.1.102.55 and Previous 0 Day Exploit
2011-12-08/a>Adrien de BeaupreMicrosoft Security Bulletin Advance Notification for December 2011
2011-11-16/a>Jason LamPotential 0-day on Bind 9
2011-11-08/a>Swa FrantzenMicrosoft November 2011 Black Tuesday Overview
2011-11-08/a>Swa FrantzenAbobe November 2011 Black Tuesday Overview
2011-11-08/a>Swa FrantzenApple Black Tuesday
2011-11-03/a>Guy BruneauNovember 2011 Patch Tuesday Pre-release
2011-10-11/a>Swa FrantzenMicrosoft Black Tuesday Overview October 2011
2011-09-13/a>Swa FrantzenMicrosoft September 2011 Black Tuesday
2011-09-13/a>Swa FrantzenAdobe September 2011 Black Tuesday overview
2011-09-09/a>Johannes UllrichEarly Patch Tuesday Today: Microsoft September 2011 Patches
2011-09-08/a>Mark HofmanMicrosoft has released their advanced notification for patch Tuesday. 15 Vulnerabilities to be addressed. more here --> http://blogs.technet.com/b/msrc/archive/2011/09/08/advanced-notification-for-the-september-2011-bulletin-release.aspx
2011-08-09/a>Swa FrantzenMicrosoft August 2011 Black Tuesday Overview
2011-08-09/a>Swa FrantzenAdobe August 2011 Black Tuesday Overview
2011-07-12/a>Swa FrantzenMicrosoft July 2011 Black Tuesday Overview
2011-07-10/a>Raul SilesJailbreakme Takes Advantage of 0-day PDF Vuln in Apple iOS Devices
2011-06-14/a>Swa FrantzenAdobe releases patches
2011-06-14/a>Swa FrantzenMicrosoft June 2011 Black Tuesday Overview
2011-05-10/a>Swa FrantzenMay 2011 Microsoft Black Tuesday Overview
2011-05-06/a>Richard PorterUnpatched Exploit: Skype for MAC
2011-04-11/a>Jim ClausingApril 2011 Microsoft Black Tuesday Summary
2011-04-08/a>Johannes UllrichDark Black Tuesday Coming Up: 17 Microsoft Bulletins
2011-03-08/a>Jim ClausingMarch 2011 Microsoft Black Tuesday Summary
2011-02-08/a>Joel EslerFeburary 2011 Microsoft Black Tuesday Summary
2011-01-11/a>Kevin ShorttJanuary 2011 Microsoft Black Tuesday Summary
2011-01-11/a>Kevin ShorttSpam Cannons on Holiday
2011-01-08/a>Guy BruneauJanuary 2011 Patch Tuesday Pre-release
2010-12-23/a>Mark HofmanIE 0 Day, just in time for Christmas
2010-12-22/a>John BambenekIIS 7.5 0-Day DoS (processing FTP requests)
2010-12-20/a>Guy BruneauPatch Issues with Outlook 2007
2010-12-14/a>Manuel Humberto Santander PelaezDecember 2010 Microsoft Black Tuesday Summary
2010-11-24/a>Bojan ZdrnjaPrivilege escalation 0-day in almost all Windows versions
2010-11-09/a>Johannes UllrichNovember 2010 Microsoft Black Tuesday Summary
2010-11-01/a>Manuel Humberto Santander PelaezCVE-2010-3654 exploit in the wild
2010-10-28/a>Manuel Humberto Santander PelaezCVE-2010-3654 - New dangerous 0-day authplay library adobe products vulnerability
2010-10-26/a>Pedro BuenoFirefox news
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote Access Tools
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Tunnels - to Split or not to Split?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - VPN Architectures – SSL or IPSec?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - Remote User VPN Access – Are things getting too easy, or too hard?
2010-10-19/a>Rob VandenBrinkCyber Security Awareness Month - Day 19 - VPN and Remote Access Tools
2010-10-12/a>Adrien de BeaupreOctober 2010 Microsoft Black Tuesday Summary
2010-10-11/a>Adrien de BeaupreOT: Happy Thanksgiving Day Canada
2010-10-08/a>Rick WannerPatch Tuesday Pre-release -- 16 updates
2010-09-14/a>Adrien de BeaupreSeptember 2010 Microsoft Black Tuesday Summary
2010-08-10/a>Jim ClausingAugust 2010 Micrsoft Black Tuesday Summary
2010-08-07/a>Stephen HallCountdown to Tuesday...
2010-07-13/a>Jim ClausingJuly 2010 Microsoft Black Tuesday Summary
2010-06-08/a>Manuel Humberto Santander PelaezJune 2010 Microsoft Black Tuesday Summary
2010-06-03/a>Guy BruneauMicrosoft Patch Tuesday June 2010 Pre-Release
2010-05-11/a>Scott FendleyMay 2010 Microsoft Patches
2010-05-08/a>Guy BruneauMicrosoft Patch Tuesday May 2010 Pre-Release
2010-04-13/a>Johannes UllrichMicrosoft April 2010 Patch Tuesday
2010-04-08/a>Guy BruneauMicrosoft Patch Tuesday April 2010 Pre-Release
2010-03-09/a>John BambenekMarch 2010 - Microsoft Patch Tuesday Diary
2010-03-01/a>Mark HofmanIE 0-day using .hlp files
2010-02-09/a>Adrien de BeaupreWhen is a 0day not a 0day? Samba symlink bad default config
2010-02-09/a>Johannes UllrichFebruary 2010 Black Tuesday Overview
2010-02-04/a>Johannes UllrichMicrosoft Patch Tuesday Pre-Release
2010-01-21/a>Johannes UllrichMicrosoft January Out of Band Patch
2010-01-14/a>Bojan Zdrnja0-day vulnerability in Internet Explorer 6, 7 and 8
2010-01-12/a>Johannes UllrichMicrosoft Security Bulletin: January 2010
2010-01-12/a>Johannes UllrichPre-Announced Adobe Reader and Acrobat Patch Found!
2010-01-07/a>Daniel WesemannStatic analysis of malicious PDFs
2010-01-07/a>Daniel WesemannStatic analysis of malicous PDFs (Part #2)
2009-12-27/a>Patrick NolanPressure increasing for Microsoft to patch IIS 0 day
2009-12-15/a>Johannes UllrichAdobe 0-day in the wild - again
2009-12-08/a>Deborah HaleDecember 2009 Black Tuesday Overview
2009-11-22/a>Marcus SachsIE6 and IE7 0-Day Reported
2009-11-10/a>Swa FrantzenMicrosoft November Black Tuesday Overview
2009-10-13/a>Johannes UllrichMicrosoft October 2009 Black Tuesday Overview
2009-09-08/a>Adrien de BeaupreMicrosoft Security Advisory 975191 Revised
2009-09-08/a>Guy BruneauMicrosoft September 2009 Black Tuesday Overview
2009-09-04/a>Adrien de BeaupreVulnerabilities (plural) in MS IIS FTP Service 5.0, 5.1. 6.0, 7.0
2009-08-31/a>Pedro BuenoMicrosoft IIS 5/6 FTP 0Day released
2009-08-11/a>Swa FrantzenMicrosoft August 2009 Black Tuesday Overview
2009-07-22/a>Bojan ZdrnjaYA0D (Yet Another 0-Day) in Adobe Flash player
2009-07-17/a>Bojan ZdrnjaA new fascinating Linux kernel vulnerability
2009-07-14/a>Swa FrantzenMicrosoft July Black Tuesday Overview
2009-07-14/a>Swa FrantzenOracle Black Tuesday
2009-07-06/a>Stephen Hall0-day in Microsoft DirectShow (msvidctl.dll) used in drive-by attacks
2009-07-03/a>Adrien de BeaupreHappy 4th of July!
2009-06-09/a>Swa FrantzenMicrosoft June Black Tuesday Overview
2009-06-09/a>Swa FrantzenAdobe June Black Tuesday upgrades
2009-05-12/a>Swa FrantzenMSFT's version of responsible disclosure
2009-05-12/a>Swa FrantzenMay Black Tuesday Overview
2009-04-29/a>Jason LamTwo Adobe 0-day vulnerabilities
2009-04-14/a>Swa FrantzenApril Black Tuesday Overview
2009-03-18/a>Adrien de BeaupreAdobe Security Bulletin Adobe Reader and Acrobat
2009-03-10/a>Swa FrantzenMarch black Tuesday overview
2009-02-25/a>Andre LudwigAdobe Acrobat pdf 0-day exploit, No JavaScript needed!
2009-02-10/a>Swa FrantzenFebruary Black Tuesday Overview
2009-01-13/a>Johannes UllrichJanuary Black Tuesday Overview
2008-12-12/a>Johannes UllrichMSIE 0-day Spreading Via SQL Injection
2008-12-12/a>Kevin ListonIE7 0day expanded to include IE6 and IE8(beta)
2008-12-10/a>Bojan Zdrnja0-day exploit for Internet Explorer in the wild
2008-12-09/a>Swa FrantzenDecember Black Tuesday Overview
2008-11-11/a>Swa FrantzenNovember Black Tuesday Overview
2008-11-02/a>Adrien de BeaupreDaylight saving time
2008-10-14/a>Swa FrantzenOctober Black Tuesday Overview
2008-09-09/a>Swa FrantzenSeptember 2008 Black Tuesday Overview
2008-08-12/a>Stephen HallAugust 2008 Black Tuesday Overview
2008-07-08/a>Swa FrantzenJuly 2008 black tuesday overview
2008-06-10/a>Swa FrantzenJune 2008 Black Tuesday Overview
2008-05-13/a>Swa FrantzenMay 2008 black tuesday overview
2008-04-08/a>Swa FrantzenApril 2008 - Black Tuesday Overview
2008-03-11/a>Swa FrantzenMarch Black Tuesday Overview
2008-02-12/a>Swa FrantzenFebruary Black Tuesday Overview
2008-01-08/a>Swa FrantzenJanuary Black Tuesday overview
2007-12-11/a>Swa FrantzenDecember black tuesday overview
2007-11-13/a>Swa Frantzennovember black tuesday overview
2007-10-09/a>Swa FrantzenOctober Black Tuesday overview
2007-09-11/a>Swa FrantzenSeptember microsoft patch overview
2007-08-14/a>Swa FrantzenAugust 'Black Tuesday' overview
2007-07-10/a>Swa FrantzenJuly 'Black Tuesday' overview
2007-06-12/a>Johannes UllrichJune 2007, Microsoft Patch Tuesday Overview.
2007-05-08/a>Swa FrantzenMay 2007, Black Tuesday patch overview
2007-04-10/a>Swa FrantzenMicrosoft black Tuesday patches - April 2007
2007-04-03/a>Swa Frantzen* Microsoft out of cycle patch
2007-02-13/a>Swa FrantzenMicrosoft Black Tuesday patches - February 2007
2007-01-09/a>Swa FrantzenMicrosoft Patches - January 2007 - overview
2006-12-12/a>Swa FrantzenMicrosoft Black Tuesday - December 2006 overview
2006-12-12/a>Robert DanfordMS06-078: 2 Windows Media Format Vulnerabilities (CVE-2006-4702, CVE-2006-6134)
2006-11-29/a>Toby KohlenbergWeek of Oracle bugs cancelled
2006-11-14/a>Swa FrantzenMicrosoft Black Tuesday Overview
2006-10-09/a>Swa FrantzenMicrosoft black tuesday - October 2006 STATUS
2006-09-28/a>Swa FrantzenPowerpoint, yet another new vulnerability
2006-09-28/a>Swa FrantzenMSIE: One patched, one pops up again (setslice)
2006-09-22/a>Swa FrantzenYellow: MSIE VML exploit spreading
2006-09-19/a>Swa FrantzenYet another MSIE 0-day: VML
2006-09-15/a>Swa FrantzenMSIE DirectAnimation ActiveX 0-day update
2006-09-12/a>Swa FrantzenMicrosoft security patches for September 2006

CANADA

2014-06-17/a>Rob VandenBrinkCanada's Anti-Spam Legislation (CASL) 2014
2010-10-11/a>Adrien de BeaupreOT: Happy Thanksgiving Day Canada
2010-10-03/a>Adrien de BeaupreCanada's Cyber Security Strategy released today