labs
Dark Angels | ESXi Ransomware Borrows Code & Victimology From RagnarLocker
Learn how the Dark Angels ransomware targeting Johnson Controls' ESXi servers shares significant overlap with the notorious RagnarLocker.
Read More
Learn how the Dark Angels ransomware targeting Johnson Controls' ESXi servers shares significant overlap with the notorious RagnarLocker.
Vulnerable instances of Progess WS_FTP are being targeted by opportunistic attackers leveraging LOLBins to deliver Metasploit and remote access payloads.
Pakistan-aligned threat actor weaponizes fake YouTube apps on the Android platform to deliver mobile remote access trojan spyware.
Cloud credentials stealing campaign expands to target Azure and Google Cloud via unpatched web app vulnerabilities.
Read this technical breakdown of Rhysida ransomware and learn about its recent attacks on government institutions. Hunting rules and indicators included.
Availability of leaked Babuk source code is fuelling a proliferation of file lockers targeting VMware ESXi.
A sophisticated new toolset is being used to harvest credentials from multiple cloud service providers, including AWS SES and Microsoft Office 365.
New Linux version of the IceFire ransomware have been observed in recent network intrusions of media and entertainment enterprises.