THE INVINCEA BLOG

Spear-phishing, Watering Holes, Drive-bys…The Case for Invincea

There really isn’t any room for debate and I’ve yet to find a single security pro who disagrees…the user is the primary target. Spear-phishing, watering hole attacks, drive-bys, etc – these are the new favored attack vectors for our adversaries. … Read More »

Update on WTOP/FedNewsRadio Drive-by, DoL Watering Hole and Anwsers to some FAQs

As of 5.15.13, we understand from multiple sources that the WTOP and FedNewsRadio servers have been cleaned of the exploit and the all clear has been sounded. From Invincea’s perspective, it is important to point out that anytime an organization … Read More »

K.I.A. – WTOP.com, FedNewsRadio and Tech Blogger John Dvorak Blog Site Hijacked – Exploits Java and Adobe to Distribute Fake A/V Software

UPDATE: Due to heavy demand, we held a webinar on Friday 5.10.13 to discuss the attack against the WTOP and FedNewsRadio websites as well as the watering hole attacks against the U.S. Department of Labor website. For those interested, a recording … Read More »

K.I.A. – WTOP.com, FedNewsRadio and Tech Blogger John Dvorak Blog Site Hijacked – Exploits Java and Adobe to Distribute Fake A/V

UPDATE: Due to heavy demand, we are holding  a webinar on Friday 5.24.13 at 11:00 am EDT to discuss the attack against the WTOP and FedNewsRadio websites as well as the watering hole attacks against the U.S. Department of Labor … Read More »

Part 2 – K.I.A. – US Dept. Labor Watering Hole Pushing Poison Ivy Via IE8 Zero-Day

UPDATE 3:35 pm 5.6.13 – Webinar detailing findings and methods Invincea used to detect, thwart and analyze to be held on Friday May 10th, register if you’d like by going here Part 1 is available here On Wednesday May 1st, … Read More »

Part 1 – K.I.A. – US Dept. Labor Website Pushing Poison Ivy – CVE-2012-4792

UPDATED 11:30 am 5.4.13 – Correction - Microsoft confirms exploit is a zero-day as written up in Part 2 UPDATED 8:50 am 5.2.13 – Correction regarding Google black-holing of domain – details in analysis below UPDATED 2:47 pm 5.1.13 – Now available … Read More »

K.I.A. – Java CVE 2013-2423 Via New and Improved Cool EK

Java continues to be the most significant vulnerability being exploited on individual machines and enterprise networks today.  As we previously described, most enterprises cannot uninstall Java, and worse, cannot upgrade Java to the latest version even as Oracle comes out … Read More »

K.I.A. – Kelihos Trojan/RedKit EK Exploiting Boston Marathon Attacks

On the heels of national tragedies an unfortunate element that consistently arises now is exploitation of the tragedy often by cyber means. The Boston Marathon Bombing is no exception. On the morning of April 17, we noticed a strange entry … Read More »

News You Can Use

The latest and most important InfoSec news gathered in one place. Here are the stories Invincea was talking about this week: Warning! Hackers are exploiting Texas explosion news to spread malware – Naked Security Once again, cybercriminals are leaping at … Read More »

News You Can Use

The latest and most important InfoSec news gathered in one place. Here are the stories Invincea was talking about this week: Cyber-Attacks on Infrastructure Firms Highlight Need for New Defenses – eWeek Spear-phishing against energy firms and online attacks targeting … Read More »

Page 1 of 1812345...Last »