Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

research

20 articles

Elastic Security Labs research Dec 11

NANOREMOTE, cousin of FINALDRAFT

The fully-featured backdoor we call NANOREMOTE shares characteristics with malware described in REF7707 and is similar to the FINALDRAFT implant.

Elastic Security Labs → Details

WeLiveSecurity research Dec 10

Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece

Interpreting the vast cybersecurity vendor landscape through the lens of industry analysts and testing authorities can immensely enhance your cyber-resilience.

WeLiveSecurity → Details

PortSwigger Research research Dec 10

The Fragile Lock: Novel Bypasses For SAML Authentication

TLDR This post shows how to achieve a full authentication bypass in the Ruby and PHP SAML ecosystem by exploiting several parser-level inconsistencies: inclu...

T1556

PortSwigger Research → Details

WeLiveSecurity research Dec 9

The big catch: How whaling attacks target top executives

Is your organization’s senior leadership vulnerable to a cyber-harpooning? Learn how to keep them safe.

WeLiveSecurity → Details

Elastic Security Labs research Dec 5

Automating detection tuning requests with Kibana cases

Learn how to automate detection rule tuning requests in Elastic Security. This guide shows how to add custom fields to Cases, create a rule to detect tuning ...

Elastic Security Labs → Details

WeLiveSecurity research Dec 4

Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture

Identity is effectively the new network boundary. It must be protected at all costs.

T1566

WeLiveSecurity → Details

WeLiveSecurity research Dec 2

MuddyWater: Snakes by the riverbank

MuddyWater targets critical infrastructure in Israel and Egypt, relying on custom malware, improved tactics, and a predictable playbook

WeLiveSecurity → Details

WeLiveSecurity research GitHub Dec 1

Oversharing is not caring: What’s at stake if your employees post too much online

From LinkedIn to X, GitHub to Instagram, there are plenty of opportunities to share work-related information. But posting could also get your company into tr...

WeLiveSecurity → Details

WeLiveSecurity research Nov 28

This month in security with Tony Anscombe – November 2025 edition

Data exposure by top AI companies, the Akira ransomware haul, Operation Endgame against major malware families, and more of this month's cybersecurity news

WeLiveSecurity → Details

WeLiveSecurity research Nov 27

What parents should know to protect their children from doxxing

Online disagreements among young people can easily spiral out of control. Parents need to understand what’s at stake.

WeLiveSecurity → Details

WeLiveSecurity research Nov 25

Influencers in the crosshairs: How cybercriminals are targeting content creators

Social media influencers can provide reach and trust for scams and malware distribution. Robust account protection is key to stopping the fraudsters.

WeLiveSecurity → Details

WeLiveSecurity research Nov 24

MDR is the answer – now, what’s the question?

Why your business needs the best-of-breed combination of technology and human expertise

WeLiveSecurity → Details

WeLiveSecurity research Intel Nov 20

The OSINT advantage: Find your weak spots before attackers do

Here’s how open-source intelligence helps trace your digital footprint and uncover your weak points, plus a few essential tools to connect the dots

WeLiveSecurity → Details

WeLiveSecurity research Nov 19

PlushDaemon compromises network devices for adversary-in-the-middle attacks

ESET researchers have discovered a network implant used by the China-aligned PlushDaemon APT group to perform adversary-in-the-middle attacks

T1557

WeLiveSecurity → Details

WeLiveSecurity research Nov 17

What if your romantic AI chatbot can’t keep a secret?

Does your chatbot know too much? Here's why you should think twice before you tell your AI companion everything.

WeLiveSecurity → Details

Elastic Security Labs research Nov 15

RONINGLOADER: DragonBreath’s New Path to PPL Abuse

Elastic Security Labs uncovers RONINGLOADER, a multi-stage loader deploying DragonBreath’s updated gh0st RAT variant. The campaign weaponizes signed drivers,...

Elastic Security Labs → Details

WeLiveSecurity research Nov 13

How password managers can be hacked – and how to stay safe

Look no further to learn how cybercriminals could try to crack your vault and how you can keep your logins safe

WeLiveSecurity → Details

PortSwigger Research research Nov 11

Introducing HTTP Anomaly Rank

HTTP Anomaly Rank If you've ever used Burp Intruder or Turbo Intruder, you'll be familiar with the ritual of manually digging through thousands of responses ...

PortSwigger Research → Details

WeLiveSecurity research Nov 11

Why shadow AI could be your biggest security blind spot

From unintentional data leakage to buggy code, here’s why you should care about unsanctioned AI use in your company

WeLiveSecurity → Details

WeLiveSecurity research Nov 7

In memoriam: David Harley

Former colleagues and friends remember the cybersecurity researcher, author, and mentor whose work bridged the human and technical sides of security

WeLiveSecurity → Details

«Previous page 1 ... 22 23 24 25 26 ... 37 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA