Skip to main content

Threats Tagged 'analysis'

View all threats tagged with 'analysis'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: analysis

Threats Tagged 'analysis'

Click on any threat for detailed analysis and mitigation recommendations

This content describes a newly built free VMA 486 Emulator and VAXD_VM that includes a machine state analyzer capable of freezing, saving, loading, disassembling, and patching machine memory during execution. It supports running legacy operating systems such as DOS and Windows 3.x, as well as Windows 7 in a VM environment. The post is primarily an announcement of a tool with analysis capabilities rather than a security vulnerability or threat.

Join the discussion

This analysis covers a Windows-targeted cyber campaign involving social engineering via fake interviews leading to cryptocurrency theft. The campaign notably did not use DPRK malware but leveraged known malware-as-a-service (MaaS) tools and unidentified Go and Rust-based stealers and remote access trojans (RATs). The threat actor may be using DPRK tradecraft as a false flag to confuse attribution, possibly indicating Russian operators. The campaign targets web3 organizations and involves a multi-stage payload delivery chain using signed ClickOnce applications.

Join the discussion

CVE-2026-17583 is a vulnerability in Thermo Fisher's Applied Biosystems human identification instruments where forensic DNA evidence files (.fsa and .hid) can be altered between creation and analysis without detection. Researchers demonstrated that these files could be modified in about 45 minutes to merge DNA profiles into a single file that appears unaltered since 2015. Thermo Fisher issued an update adding digital signatures to files created after the patch, but no retroactive validation exists for older files, and some end-of-life products do not receive updates. This leaves historical forensic DNA evidence files vulnerable to undetectable tampering.

Join the discussion

The state of vibe-coded app security: my analysis of 549 self-described AI-generated repos (study + raw data) Source: https://ogbuilds.ai/studies/vibe-coded-security

Join the discussion

SOF-ELK is a free and open-source log and NetFlow analysis platform built on the Elastic Stack, designed for security operations and forensic analysis. It is distributed as a natively bootable VM for x86 and ARM architectures and can also be deployed via an Ansible playbook. The platform supports live data ingestion and static file analysis, providing numerous parsers and dashboards. The latest release is based on Ubuntu 26.04 and includes updates to improve performance and user experience. This is a community resource primarily intended for operational, educational, and testing purposes.

Join the discussion

A new MIPS ELF botnet malware sample has been discovered that targets IoT and gateway devices. It uses automated credential-based access with hardcoded default credentials to propagate. The malware downloads and executes secondary payloads using standard busybox commands. Detection rates on VirusTotal are currently low. Network defenders are advised to check for suspicious login attempts and ensure default passwords on IoT devices are changed.

Join the discussion

This entry describes a Discord server community focused on binary security research topics such as reverse engineering, binary obfuscation, exploit development, and malware analysis. It is a community resource rather than a security threat or vulnerability. No specific vulnerability, exploit, or attack vector is described.

Join the discussion

This analysis presents a corpus of 99 adversarial Portable Executable (PE) files designed to explore how major PE analysis tools behave when confronted with deliberately malformed but loadable binaries. The study identifies different anomaly patterns such as entrypoint redirection, overlapping sections, header inconsistencies, and more. It evaluates six common tools used in exploit development workflows, revealing varying behaviors including masking of anomalies, crashes, or lack of anomaly visibility. The research highlights how malformed PE structures can be leveraged for parser differentials, crash primitives, metadata confusion, loader inconsistencies, and analysis evasion.

Join the discussion
0

Windows 11's input pipeline causes typed passwords from third-party applications like PuTTY, WinSCP, and MySQL to appear in system process memory such as LSASS.exe, Defender (MsMpEng.exe), and ctfmon.exe. This is due to Windows telemetry and text input buffering, not malicious credential harvesting. Passwords may remain in ctfmon.exe memory even after application closure, posing a risk if non-admin malware accesses that process. Credential Guard does not protect these third-party passwords as they are not Windows authentication credentials. This behavior is architectural and expected, not a vulnerability, but it creates a real risk of password exposure through memory forensics or malware. Mitigations include using secure credential APIs, key-based authentication, password managers with secure injection, and avoiding typing passwords into standard text input fields.

Join the discussion

This entry describes a new update to OSINTDomain, a platform for domain OSINT analysis that now includes an AI assistant for interpreting technical data and prioritizing findings. It is a security tool update rather than a vulnerability or threat. There is no indication of a security flaw, exploit, or vulnerability in the information provided. The update aims to enhance analysis capabilities and reporting for cybersecurity professionals.

Join the discussion

Showing 1 to 10 of 64 results

Filters:Tag: analysis
Page 1 of 7
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses