Defensive Security Podcast Episode 245

https://www.bankinfosecurity.com/judge-rules-insurer-must-pay-for-ransomware-damage-a-13673

https://www.zdnet.com/google-amp/article/new-york-state-wants-to-ban-government-agencies-from-paying-ransomware-demands/

https://www.bankinfosecurity.com/nist…

Read More >>

Women in Security: Security Technical Project Manager

We continue to see large-scale online security attacks affecting corporations and public institutions. These attacks are becoming more and more sophisticated, making it harder to protect yourself. The constant evolution of attacks requires innovative s…

Read More >>

CVE-2019-19781: Citrix ADC RCE vulnerability

A week before the 2019 holidays Citrix announced that an authentication bypass vulnerability was discovered in multiple Citrix products. The affected products are the Citrix Application Delivery Controller (formerly known as NetScaler AD), Citrix Gatew…

Read More >>

Smart OSINT Collection of Common IOC Types

Smart OSINT Collection of Common IOC (Indicator of compromise) Types

This application is designed to assist security analysts and researchers with the collection and assessment of common IOC types. Accepted IOCs currently include IP addresses, do…

Read More >>

Defensive Security Podcast Episode 244

https://www.securityweek.com/attacker-installs-backdoor-blocks-others-exploiting-citrix-adc-vulnerability
https://www.securityweek.com/court-approves-equifax-data-breach-settlement
https://www.infosecurity-magazine.com/news/equifax-breach-settlement-co…

Read More >>

Abusing the Service Workers API

The Service Worker web API is a powerful new API for web browsers. During our research, we have found several ways attackers can leverage this API to enhance their low-to-medium risk findings into a powerful and meaningful attack. By…

Read More >>