Threat Research Blog

  • How to Write a PoC for an Uninitialized Smart Contract Vulnerability in BadgerDAO Using Foundry

    How to Write a PoC for an Uninitialized Smart Contract Vulnerability in BadgerDAO Using Foundry

    TL;DR In this post, we’re going to learn how Foundry can be used to write a proof of concept (PoC) for uninitialized smart contract vulnerabilities. We will take a look at and exploit a simple...

    Read Article
  • CyberArk Named a Leader in the 2022 Gartner® Magic Quadrant™ for Privileged Access Management – again.

    View the Report
  • White Phoenix: Beating Intermittent Encryption

    White Phoenix: Beating Intermittent Encryption

    Recently, a new trend has emerged in the world of ransomware: intermittent encryption, the partial encryption of targeted files. Many ransomware groups, such as BlackCat and Play, have adopted...

    Read Article
  • Fantastic Rootkits and Where to Find Them (Part 2)

    Fantastic Rootkits and Where to Find Them (Part 2)

    Know Your Enemy In the previous post (Part 1), we covered several rootkit technique implementations. Now we will focus on kernel rootkit analysis, looking at two case studies of rootkits found in...

    Read Article
  • Breaking Docker Named Pipes SYSTEMatically: Docker Desktop Privilege Escalation – Part 2

    Breaking Docker Named Pipes SYSTEMatically: Docker Desktop Privilege Escalation – Part 2

    In the previous blog post, we described how the Docker research started and showed how we could gain a full privilege escalation through a vulnerability in Docker Desktop. In this follow-up blog...

    Read Article
  • The (Not so) Secret War on Discord

    The (Not so) Secret War on Discord

    CyberArk Malware Research Team Abstract CyberArk Labs discovered a new malware called Vare that is distributed over the popular chatting service, Discord. Vare has been used to target new malware...

    Read Article
  • Persistence Techniques That Persist

    Persistence Techniques That Persist

    Abstract Once threat actors gain a foothold on a system, they must implement techniques to maintain that access, even in the event of restarts, updates in credentials or any other type of change...

    Read Article
  • Phishing as a Service

    Phishing as a Service

    Introduction Everyone knows what phishing is. It has been around for more than two decades. Now it seems that phishing is more accessible than before. This blog covers how malicious actors can...

    Read Article
  • The Linux Kernel and the Cursed Driver

    The Linux Kernel and the Cursed Driver

    Introduction NTFS is a filesystem developed by Microsoft that was introduced in 1993. Since then, it has become the primary filesystem for Windows. In recent years, the need for an NTFS...

    Read Article
  • Breaking Docker Named Pipes SYSTEMatically: Docker Desktop Privilege Escalation – Part 1

    Breaking Docker Named Pipes SYSTEMatically: Docker Desktop Privilege Escalation – Part 1

    Everything started when I was researching Windows containers. It required installing Docker Desktop for Windows, and I couldn’t help but notice that there were many Docker processes. Since some of...

    Read Article
  • Inglourious Drivers – A Journey of Finding Vulnerabilities in Drivers

    Inglourious Drivers – A Journey of Finding Vulnerabilities in Drivers

    TL;DR I discovered multiple bugs in OEM vendors for peripheral devices, which affected many users of these OEM vendors (Razer, EVGA, MSI, AMI). Many of the vulnerabilities originated in a...

    Read Article
  • Chatting Our Way Into Creating a Polymorphic Malware

    Chatting Our Way Into Creating a Polymorphic Malware

    Abstract ChatGPT took the world by storm being released less than two months ago, it has become prominent and is used everywhere, for a wide variety of tasks – from automation tasks to the...

    Read Article
  • What I Learned from Analyzing a Caching Vulnerability in Istio

    What I Learned from Analyzing a Caching Vulnerability in Istio

    TL;DR Istio is an open-source service mash that can layer over applications. Studying CVE-2021-34824 in Istio will allow us to dive into some concepts of Istio and service meshes in general. We...

    Read Article
  • Decentralized Identity Attack Surface – Part 2

    Decentralized Identity Attack Surface – Part 2

    Introduction This is the second part of our Decentralized Identity (DID) blog series. In case you’re not familiar with DID concepts, we highly encourage you to start with the first part. This time...

    Read Article
  • Decentralized Identity Attack Surface – Part 1

    Decentralized Identity Attack Surface – Part 1

    Introduction Who are you? That’s a hard question to answer. Many philosophers have been fascinated with this question for years. Who are you in cyberspace? Your digital identity is comprised of...

    Read Article
  • Fantastic Rootkits: And Where to Find Them (Part 1)

    Fantastic Rootkits: And Where to Find Them (Part 1)

    Introduction In this blog series, we will cover the topic of rootkits — how they are built and the basics of kernel driver analysis — specifically on the Windows platform. In this first part, we...

    Read Article
  • Colorful Vulnerabilities

    Colorful Vulnerabilities

    Our love for gaming alongside finding bugs led us back to the good ol’ question: Is it true that the more RGB colors you have (except for your gaming chair, of course), the more skill...

    Read Article
  • Understanding Windows Containers Communication

    Understanding Windows Containers Communication

    Several years ago, when I spoke with people about containers, most of them were not familiar with the term. Today, it is unquestionably one of the most popular technologies being used in DevOps...

    Read Article
  • Trust Me, I’m a Robot: Can We Trust RPA With Our Most Guarded Secrets?

    Trust Me, I’m a Robot: Can We Trust RPA With Our Most Guarded Secrets?

    In our complicated and challenging enterprise world, trust is not just important — it’s a vital link in the long chain of enterprise success. If you’ve ever managed people who didn’t trust one...

    Read Article
  • Inside Matanbuchus: A Quirky Loader

    Inside Matanbuchus: A Quirky Loader

    An in-depth analysis of Matanbuchus loader’s tricks and loading techniques Matanbuchus is a Malware-as-a-Service loader that has been sold on underground markets for more than one year....

    Read Article
  • That Pipe is Still Leaking: Revisiting the RDP Named Pipe Vulnerability

    That Pipe is Still Leaking: Revisiting the RDP Named Pipe Vulnerability

    On January 11, 2022, we published a blog post describing the details of CVE-2022-21893, a Remote Desktop vulnerability that we found and reported to Microsoft. After analyzing the patch that fixed...

    Read Article
  • loading
    Loading More...