Latest Posts

Latest Posts

My Favourite Security-focused GPO: Stopping Script Execution with File Associations

Some time ago, I stumbled upon an excellent post by Red Canary[1] that introduced a clever method to prevent users from accidentally… Cont...

Sp123 4 Nov, 2024

Unransomware: From Zero to Full Recovery in a Blink

This blog post discusses how we, DCSO’s Incident Response Team (DIRT), were able to help an Akira ransomware victim restore their business c...

Sp123 4 Nov, 2024

북한 APT 리퍼(Reaper)에서 만든 탈북민 사칭 한국해양수산연수원 타겟 인것으로 추측이 되는 악성코드-정보접근권.lnk(2024.11.1)

오늘은 세계적으로 유명한 APT 조직 한 APT 북한 APT 리퍼(Reaper,APT37)에서 만든 탈북민 사칭 한국해양수산연수원 타겟 인것으로 추측이 되는 악성코드-정보접근권.lnk(2024.11.1)에 대해 글을 적어보겠습니다. 일명 RoKRAT한...

Sp123 3 Nov, 2024

Update: pdfid.py Version 0.2.9

This small update brings support for ZIP 2.0 via the pyzipper module. pdfid_v0_2_9.zip ( http ) MD5: 57C5AE391116B79E1F90FFF7BBB36331 SH...

Sp123 2 Nov, 2024

Visibility is key: Strengthening security with Sysdig

As digital operations expand, the financial industry is facing heightened regulatory and security demands. With the European Union’s Digita...

Sp123 1 Nov, 2024

LottieFiles Supply Chain Attack: Compromised npm Package Targets Cryptocurrency Wallets

LottieFiles Supply Chain Attack: Compromised npm Package Targets Cryptocurrency Wallets LottieFiles recently disclosed a major supply chain...

Sp123 1 Nov, 2024

Dark Web Profile: Tropic Trooper (APT23)

Dark Web Profile: Tropic Trooper (APT23) Tropic Trooper, also known as Pirate Panda and APT 23, is a Chinese state-sponsored cyber threat g...

Sp123 1 Nov, 2024

ServiceNow Now Platform Vulnerabilities Enable RCE and SQL Injection Risks (CVE-2024-8923, CVE-2024-8924) – Patch Now

ServiceNow Now Platform Vulnerabilities Enable RCE and SQL Injection Risks (CVE-2024-8923, CVE-2024-8924) – Patch Now ServiceNow’s Now Plat...

Sp123 1 Nov, 2024