Chinese UNC6384 Malware Campaign Exploits Cambodia Thailand Crisis
Diplomatic entities targeted in spearphishing campaign by UNC6384 cyber espionage.
Recent content on Martin Kubečka
Diplomatic entities targeted in spearphishing campaign by UNC6384 cyber espionage.
Deep dive analysis of an opportunistic phishing campaign delivering Katz Stealer and Remcos RAT.
A DOM-based XSS vulnerability in Logseq version 0.10.9 allows Remote Code Execution by injecting malicious JavaScript through unsanitized plugin README content combined with insufficient protocol validation.
Reflected XSS vulnerability in multiple query parameters of Combodo iTop’s render endpoint allows JavaScript injection and execution.
I am a Cybersecurity Analyst with main interest in Cyber Defense, Cyber Threat Intelligence, Open-Source Intelligence Techniques and Social Engineering. I completed my Master’s degree at the Faculty of Electrical Engineering and Information Technology of the Slovak University of Technology in Bratislava, where I pursued Computer Science with a focus on the security of information…
#21 : Evading EDR Subtitle: The Definitive Guide to Defeating Endpoint Detection Systems Author: Matt Hand Publication Date: September, 2023 Length: 312 Pages ISBN: 9781718503342 Publisher: No Starch Press #20 : Intelligence-Driven Incident Response Subtitle: Outwitting the Adversary, 2nd Edition Author: Rebekah Brown, Scott Roberts Publication Date: June, 2023 Length: 316 Pages ISBN:…
Enhance your digital privacy with self-hosted news aggregator.
SQL injection vulnerability in EGavilan Media's Resumes Management and Job application allows unauthenticated attackers to bypass login authentication.
Stored XSS vulnerability in FlatPress 1.2.1 allows arbitrary JavaScript execution via crafted post content.
Stored XSS vulnerability in Expense Management System 1.0 allows arbitrary JavaScript execution via expense description input.
Learn how to set up your own Recursive DNS Server at home on a Raspberry Pi 4.
Unauthenticated SQL injection vulnerability in GRANDCOM CMS allows login bypass via crafted username.
Learn about crafting and analyzing Microsoft Excel malicious macros.