Here's a report from our Security Services (MDR, Incident Response, Compromise Assessment, and SOC Consulting) for 2025: fewer high-severity incidents; CVEs in Microsoft products were most popular among attackers; and public-facing applications, valid accounts, and trusted relationships were the most popular initial vectors(>80% of attacks). For more on these and other expert insights, here’s the full report: https://t.co/SBk5WHNxxy
We know it’s been a while since our last post.
But we’re back, with great news!
We’re launching our blog, “Purpleshift,” featuring interesting articles, talks, and research for both blue and red teams.
Yeah that’s why it’s purple :)
https://t.co/h8kQbJwUsM
I am excited to speak at #BlackHat MEA 2024 in Riyadh. I'll share my research on #Google Drive for Desktop Applications and introducing DriveFS Sleuth, a tool I developed to automate forensic investigations on Google DriveFS artifacts.
#incident_response#threat_hunting
.@kaspersky's new research reveals a #macOS variant of the #HZRat backdoor targeting #WeChat and DingTalk users. Originally found on #Windows, this malware now threatens macOS, posing risks of lateral movement and data theft.
Full report 👇 https://t.co/Y0myj7XpYK
#Mozilla recently introduced a technology called Privacy-Preserving Attribution (PPA)—designed to track the effectiveness of #onlineadvertising. @kaspersky explores what PPA is and why it’s needed now.
Learn more: https://t.co/speRbV9mNv
Kaspersky uncovered seven vulns in the open-source projects #Suricata and #FreeRDP. Two of these vulns could allow attackers to execute arbitrary code on a vulnerable system, while others could enable unauthorized memory access.
Full report: https://t.co/Vx1aH4S6il
.@kaspersky's Q2 2024 Exploits & Vulnerabilities Report is here! Uncover insights on BYOVD (Bring Your Own Vulnerable Driver) attacks, the latest vulnerability stats, and a surprising Chinese symbol processing flaw.
Read the full details: https://t.co/KeETt7GQAM
@Kaspersky researchers have found a new infostealer campaign TUSK, with 19 sub-campaigns - with some of them still active.
The campaign mimics legitimate crypto-platforms and gaming sites to obtain cryptowallet credentials and other sensitive data. https://t.co/24ObqBS5cv
🚀DriveFS Sleuth supports MD5 Hash Searching!
MD5 hashes can be passed via cmdline or CSV, enabling efficient investigations by filtering synced files, even if not cached on disk.
🔗 https://t.co/5ZHQ9qR2IK
#CyberSecurity#DigitalForensics#DFIR#ThreatHunting#IncidentResponse