Discover Subdomains During A Penetration Testing Engagement
During an external penetration test, and especially if it is a black-box engagement, one of the most important steps is to find subdomains used by the target company.
During an external penetration test, and especially if it is a black-box engagement, one of the most important steps is to find subdomains used by the target company.
Read moreAccording to a recent Accenture study, more than half of organizations are not effectively defending against cyberattacks.
Read moreA security researcher has published a public exploit on Github that allows a low privileged user on all client and server windows operating systems, to gain administrative rights.
Read moreThe company detected unauthorized access to its systems where customer's Wordpress servers are hosted and managed.
Read moreA few ways to discover if any of your accounts has been hacked. Either with the help of Google Chrome or with the use of online tools.
Read moreThe influx of ransomware and supply chain attacks seen throughout 2021, many of which targeted operation- and mission-critical environments, should be a wake-up call that security is a business issue, and not just another problem for IT to solve
Read moreCheck Point Research spotted over 5300 malicious websites per week, marking it the highest since the beginning of 2021. The number of malicious websites made to trick you and obtaining your credit card and your login information, many times for well known websites as amazon.
Read moreNordPass has published a study with the top 200 most common passwords for 2021. The study covered 50 countries.
Read moreFBI has confirmed that an unnamed actor was able to gain access to the FBI's Law Enforcement Enterprise Portal (LEEP) to send the emails to thousands of recipients about a fake cyberattack.
Read moreThe objective of the attacker is to cause harm to humans using killware in the Operational Technology environment. Many similar attacks have been identified since the year 2000, even though they were not called killware back then.
Read moreAn unpatched security weakness in Azure Active Directory might be leveraged by attackers to conduct undetected brute-force attacks, according to security researchers.
Read morevulnerability in the SMS multi-factor authentication mechanism of Coinbase was used by hackers to steal funds from 6000 users
Read moreRussian tech company Yandex said that it suffered from the largest DDoS attack ever recorded in the history of the internet.
Read moreMany organizations are uploading files on their websites like pdf, word and excel without being aware that they are exposing sensitive information. You can enumerate and capture the files and its metadata.
Read moreOperators of the malware known as SolarMarker, are using an old technique called SEO poisoning to trick users to follow links on PDF documents stuffed with many SEO keywords and redirect them to malware.
Read moreA list of not so commonly used but powerful Nmap commands to help you bring your enumeration skills to the next level.
Read moreSecurity firm Wordfence released a report identifying the top security vulnerabilities and threats and common attacks against wordpress websites.
Read moreUnderstand what a zero-day exploit is and how your organization can defend against such attacks which target unknown vulnerabilities of your systems and applications.
Read more