Category: SANS Internet Storm Center, InfoCON: green

Bruteforce Scans for CrushFTP , (Tue, Mar 3rd)

CrushFTP is a Java-based open source file transfer system. It is offered for multiple operating systems. If you run a CrushFTP instance, you may remember that the software has had some serious vulnerabilities: CVE-2024-4040 (the template-injection flaw that let unauthenticated…

Wireshark 4.6.4 Released, (Mon, Mar 2nd)

Wireshark release 4.6.4 fixes 3 vulnerabilities and 15 bugs. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: Wireshark 4.6.4 Released, (Mon, Mar 2nd)

Quick Howto: ZIP Files Inside RTF, (Mon, Mar 2nd)

In diary entry “Quick Howto: Extract URLs from RTF files” I mentioned ZIP files. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: Quick Howto: ZIP Files Inside RTF, (Mon, Mar 2nd)

Fake Fedex Email Delivers Donuts!, (Fri, Feb 27th)

It&#x27s Friday, let&#x27s have a look at another simple piece of malware to close a busy week! I received a Fedex notification about a delivery. Usually, such emails are simple phishing attacks that redirect you to a fake login page…

Another day, another malicious JPEG, (Mon, Feb 23rd)

In his last two diaries, Xavier discussed recent malware campaigns that download JPEG files with embedded malicious payload[1,2]. At that point in time, I&#x27ve not come across the malicious “MSI image” myself, but while I was going over malware samples…