CVE-2021-34527
published 2021-07-02CVE-2021-34527: A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who…
PriorityP196high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.76%
100.0th percentile
A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
UPDATE July 7, 2021: The security update for Windows Server 2012, Windows Server 2016 and Windows 10, Version 1607 have been released. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. If you are unable to install these updates, see the FAQ and Workaround sections in this CVE for information on how to help protect your system from this vulnerability.
In addition to installing the updates, in order to secure your system, you must confirm that the following registry settings are set to 0 (zero) or are not defined (Note: These registry keys do not exist by default, and therefore are already at the secure setting.), also that your Group Policy setting are correct (see FAQ):
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint
NoWarningNoElevationOnInstall = 0 (DWORD) or not defined (default setting)
UpdatePromptSettings = 0 (DWORD) or not defined (default setting)
Having NoWarningNoElevationOnInstall set to 1 makes your system vulnerable by design.
UPDATE July 6, 2021: Microsoft has completed the investigation and has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. If you are unable to install these updates, see the FAQ and Workaround sections in this CVE for information on how to help protect your system from this vulnerability. See also KB5005010: Restricting installation of new printer drivers after applying the July 6, 2021 updates.
Note that the security u
Affected
53 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.18969 | 10.0.10240.18969 |
| microsoft | windows_10_1607 | < 10.0.14393.4470 | 10.0.14393.4470 |
| microsoft | windows_10_1809 | < 10.0.17763.2029 | 10.0.17763.2029 |
| microsoft | windows_10_20h2 | < 10.0.19042.1083 | 10.0.19042.1083 |
| microsoft | windows_10_21h2 | < 10.0.19044.1415 | 10.0.19044.1415 |
| microsoft | windows_10_22h2 | < 10.0.19045.2251 | 10.0.19045.2251 |
| microsoft | windows_10_version_1507 | >= 10.0.0 < 10.0.10240.18969 | 10.0.10240.18969 |
| microsoft | windows_10_version_1607 | >= 10.0.0 < 10.0.14393.4470 | 10.0.14393.4470 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2029 | 10.0.17763.2029 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1083 | 10.0.19042.1083 |
| microsoft | windows_10_version_21h2 | >= 10.0.0 < 10.0.19044.1415 | 10.0.19044.1415 |
| microsoft | windows_10_version_22h2 | >= 10.0.0 < 10.0.19045.2251 | 10.0.19045.2251 |
| microsoft | windows_11_21h2 | < 10.0.22000.318 | 10.0.22000.318 |
| microsoft | windows_11_22h2 | < 10.0.22621.674 | 10.0.22621.674 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.318 | 10.0.22000.318 |
| microsoft | windows_11_version_22h2 | >= 10.0.0 < 10.0.22621.674 | 10.0.22621.674 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20046 | 6.3.9600.20046 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < 6.1.7601.25633 | 6.1.7601.25633 |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < 6.1.7601.25633 | 6.1.7601.25633 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.0 < 6.0.6003.21138 | 6.0.6003.21138 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.0 < 6.2.9200.23383 | 6.2.9200.23383 |
| microsoft | windows_server_2012_r2 | >= 6.3.0 < 6.3.9600.20046 | 6.3.9600.20046 |
| microsoft | windows_server_2016 | < 10.0.14393.4470 | 10.0.14393.4470 |
Detection & IOCsextracted from sources · hover to see the quote
registryHKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint\NoWarningNoElevationOnInstall↗
sigma↗
Snort SIDs: 57876, 57877
- →Vice Society ransomware group actively exploited CVE-2021-34527 (PrintNightmare) to spread laterally across victim networks; defenders should monitor for lateral movement via Windows Print Spooler exploitation. ↗
- →Exploit code for PrintNightmare (CVE-2021-34527) has been incorporated into Metasploit and Mimikatz; monitor for execution of these frameworks targeting the Print Spooler service. ↗
- →PrintNightmare can be exploited via both MS-RPRN (MS Print System Remote Protocol) and MS-PAR (MS Print System Asynchronous Remote Protocol); monitor for unusual RPC calls on both protocols. ↗
- →At least 34 public PoC exploit scripts for PrintNightmare appeared on GitHub within one week of disclosure; monitor GitHub and public repositories for new exploit variants targeting Print Spooler. ↗
- →A Russian state-sponsored group was observed exploiting CVE-2021-34527 to access cloud and email accounts and exfiltrate documents; monitor for Print Spooler exploitation followed by cloud/email account access. ↗
- →PrintNightmare (CVE-2021-34527) is exploitable via the PrinterBug technique using the MS-RPRN protocol; monitor for anomalous MS-RPRN RPC traffic. ↗
- ·Having NoWarningNoElevationOnInstall set to 1 in the PointAndPrint registry key makes the system vulnerable by design, even after patching; this setting must be verified as 0 or absent. ↗
- ·The July 6, 2021 OOB patch did not fully address CVE-2021-34527; multiple researchers found it was possible to bypass the patch under certain conditions shortly after release. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vulncheck8.8HIGH
cisa8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
cisa·2021-11-03·CVSS 8.8
CVE-2021-34527 [HIGH] CWE-269 Microsoft Windows Print Spooler Remote Code Execution Vulnerability
Vulnerability: Microsoft Windows Print Spooler Remote Code Execution Vulnerability
Affected: Microsoft Windows
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.
Required Action: Apply updates per vendor instructions.
Notes: Reference CISA's ED 21-04 (https://www.cisa.gov/news-events/directives/ed-21-04-mitigate-windows-print-spooler-service-vulnerability) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-04. https://nvd.nist
Microsoft
Windows Print Spooler Remote Code Execution Vulnerability
vendor_msrc·2021-07-13·CVSS 8.8
CVE-2021-34527 [HIGH] Windows Print Spooler Remote Code Execution Vulnerability
Windows Print Spooler Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
UPDATE July 7, 2021: The security update for Windows Server 2012, Windows Server 2016 and Windows 10, Version 1607 have been released. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. If you are unable to install these updates, see the FAQ and Workaround sections in this CVE for inf
Microsoft
Windows Print Spooler Remote Code Execution Vulnerability
vendor_msrc·2021-06-08·CVSS 7.8
CVE-2021-1675 [HIGH] Windows Print Spooler Remote Code Execution Vulnerability
Windows Print Spooler Remote Code Execution Vulnerability
FAQ: Is this the vulnerability that has been referred to publicly as PrintNightmare?
No, Microsoft has assigned CVE-2021-34527 to PrintNightmare. CVE-2021-1675 is similar but distinct from CVE-2021-34527.
Windows Print Spooler Components: Windows Print Spooler Components
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5003646
Reference: https://support.microsoft.com/help/5003646
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5003635
Reference: https://support.microsoft.com
GHSA
GHSA-75f9-mm5v-2rgm: Windows Print Spooler Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-34527 [HIGH] CWE-269 GHSA-75f9-mm5v-2rgm: Windows Print Spooler Remote Code Execution Vulnerability
Windows Print Spooler Remote Code Execution Vulnerability
VulnCheck
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
vulncheck·2021·CVSS 8.8
CVE-2021-34527 [HIGH] CWE-269 Microsoft Windows Print Spooler Remote Code Execution Vulnerability
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2021-Jul; https://www.fortinet.com/blog/threat-research/affiliates-cookbook-firsthand-peek-into-operations-and-tradecraft-of-conti; https://www.crowdstrike.com/blog/magniber-ransomware-caught-using-printni
Elastic
Potential PrintNightmare File Modification
elastic_rules·CVSS 8.8
CVE-2021-34527 [HIGH] Potential PrintNightmare File Modification
Potential PrintNightmare File Modification
Detects the creation or modification of a print driver with an unusual file name. This may indicate attempts to exploit
privilege escalation vulnerabilities related to the Print Spooler service. For more information refer to CVE-2021-34527
and verify that the impacted system is investigated.
Query:
/* This rule is compatible with both Sysmon and Elastic Endpoint */
file where process.name : "spoolsv.exe" and
file.name : ("kernelbase.dll", "ntdll.dll", "kernel32.dll", "winhttp.dll", "user32.dll") and
file.path : "?:\\Windows\\System32\\spool\\drivers\\x64\\3\\*"
Elastic
Potential PrintNightmare Exploit Registry Modification
elastic_rules·CVSS 8.8
CVE-2021-34527 [HIGH] Potential PrintNightmare Exploit Registry Modification
Potential PrintNightmare Exploit Registry Modification
Detects attempts to exploit privilege escalation vulnerabilities related to the Print Spooler service. For more
information refer to CVE-2021-34527 and verify that the impacted system is investigated.
Query:
/* This rule is not compatible with Sysmon due to schema issues */
registry where process.name : "spoolsv.exe" and
(registry.path : "HKLM\\SYSTEM\\ControlSet*\\Control\\Print\\Environments\\Windows*\\Drivers\\Version-3\\mimikatz*\\Data File" or
(registry.path : "HKLM\\SYSTEM\\ControlSet*\\Control\\Print\\Environments\\Windows*\\Drivers\\Version-3\\*\\Configuration File" and
registry.data.strings : ("kernelbase.dll", "ntdll.dll", "kernel32.dll", "winhttp.dll", "user32.dll")))
Securelist
Vulnerability landscape in Q4 2025
blogs_securelist·2026-03-06
Vulnerability landscape in Q4 2025
Table of Contents
- Statistics on registered vulnerabilities
- Exploitation statistics
- Vulnerability exploitation in APT attacks
- C2 frameworks
- Notable vulnerabilities
- Conclusion and advice
Authors
- Alexander Kolesnikov
The fourth quarter of 2025 went down as one of the most intense periods on record for high-profile, critical vulnerability disclosures, hitting popular libraries and mainstream applications. Several of these vulnerabilities were picked up by attackers and exploited in the wild almost immediately.
In this report, we dive into the statistics on published vulnerabilities and exploits, as well as the known vulnerabilities leveraged with popular C2 frameworks throughout Q4 2025.
## Statistics on registered vulnerabilities
This section contains statistics on regis
Securelist
Exploits and vulnerabilities in Q4 2025
blogs_securelist·2026-03-06·CVSS 7.8
CVE-2025-55182 [HIGH] Exploits and vulnerabilities in Q4 2025
Table of Contents
Statistics on registered vulnerabilities
Exploitation statistics
Windows and Linux vulnerability exploitation
Most common published exploits
Vulnerability exploitation in APT attacks
C2 frameworks
Notable vulnerabilities
React2Shell (CVE-2025-55182): a vulnerability in React Server Components
CVE-2025-54100: command injection during the execution of curl (Invoke-WebRequest)
CVE-2025-11001: a vulnerability in 7-Zip
RediShell (CVE-2025-49844): a vulnerability in Redis
CVE-2025-24990: a vulnerability in the ltmdm64.sys driver
CVE-2025-59287: a vulnerability in Windows Server Update Services (WSUS)
Conclusion and advice
Authors
Alexander Kolesnikov
The fourth quarter of 2025 went down as one of the most intense periods on record for high-profile, critical vul
Elastic
Automating GOAD and Live Malware Labs — Elastic Security Labs
blogs_elastic·2026-02-05
Automating GOAD and Live Malware Labs — Elastic Security Labs
5 February 2026•Nic Palmer•Adrian Chen
# Automating GOAD and Live Malware Labs
Cyber Ranges as Code with Ludus and Elastic
22 min readEnablement
## Introduction: The Need for a Scalable, Automated Simulation Range
In modern security operations, detection engineering is no longer a “set it and forget it” discipline. The central challenge for any security team – and the question that underpins the entire purple-team approach is simple: how do you know whether your detection rules genuinely work? Continually validating detection logic against an ever-shifting adversary toolkit is now a fundamental requirement.
Arguably, the largest hurdle for this exercise has always been setting up the lab. Manually provisioning a multi-domain Active Directory forest, configuring it with specific vulne
Elastic
Automating GOAD and Live Malware Labs — Elastic Security Labs
blogs_elastic·2026-02-05
Automating GOAD and Live Malware Labs — Elastic Security Labs
## Automating GOAD and Live Malware Labs
Cyber Ranges as Code with Ludus and Elastic
## Introduction: The Need for a Scalable, Automated Simulation Range
In modern security operations, detection engineering is no longer a “set it and forget it” discipline. The central challenge for any security team – and the question that underpins the entire purple-team approach is simple: how do you know whether your detection rules genuinely work? Continually validating detection logic against an ever-shifting adversary toolkit is now a fundamental requirement.
Arguably, the largest hurdle for this exercise has always been setting up the lab. Manually provisioning a multi-domain Active Directory forest, configuring it with specific vulnerabilities, and deploying a separate, contained malware analys
Securelist
Exploits and vulnerabilities in Q3 2025
blogs_securelist·2025-12-03·CVSS 7.8
CVE-2025-49704 [HIGH] Exploits and vulnerabilities in Q3 2025
Table of Contents
Statistics on registered vulnerabilities
Exploitation statistics
Windows and Linux vulnerability exploitation
Most common published exploits
Vulnerability exploitation in APT attacks
C2 frameworks
Interesting vulnerabilities
ToolShell (CVE-2025-49704 and CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771): insecure deserialization and an authentication bypass
CVE-2025-8088: a directory traversal vulnerability in WinRAR
CVE-2025-41244: a privilege escalation vulnerability in VMware Aria Operations and VMware Tools
Conclusion and advice
Authors
Alexander Kolesnikov
In the third quarter, attackers continued to exploit security flaws in WinRAR, while the total number of registered vulnerabilities grew again. In this report, we examine statistics on published vuln
Securelist
Analyzing the vulnerability landscape in Q3 2025
blogs_securelist·2025-12-03
Analyzing the vulnerability landscape in Q3 2025
Table of Contents
- Statistics on registered vulnerabilities
- Exploitation statistics
- Vulnerability exploitation in APT attacks
- C2 frameworks
- Interesting vulnerabilities
- Conclusion and advice
Authors
- Alexander Kolesnikov
In the third quarter, attackers continued to exploit security flaws in WinRAR, while the total number of registered vulnerabilities grew again. In this report, we examine statistics on published vulnerabilities and exploits, the most common security issues impacting Windows and Linux, and the vulnerabilities being leveraged in APT attacks that lead to the launch of widespread C2 frameworks. The report utilizes anonymized Kaspersky Security Network data, which was consensually provided by our users, as well as information from open sources.
## Statistics on
Unit42
You Thought It Was Over? Authentication Coercion Keeps Evolving
blogs_unit42·2025-11-11·CVSS 7.5
[HIGH] You Thought It Was Over? Authentication Coercion Keeps Evolving
## Executive Summary
Imagine a scenario where malicious actors don’t need to trick you into giving up your password. They have no need to perform sophisticated social engineering attacks or exploit vulnerabilities in your operating system. Instead, they can simply force your computer to authenticate to an attacker-controlled system, effectively commanding your machine to hand over valuable credentials. This attack method is called authentication coercion.
While authentication coercion attacks such as PrintNightmare became well-known in the past few years, we have recently observed a growing trend of a new type of authentication coercion attack. These attacks focus on exploiting rarely used protocols, and they may pass through defenses written specifically for the existing known exploits.
Unit42
You Thought It Was Over? Authentication Coercion Keeps Evolving
blogs_unit42·2025-11-11
You Thought It Was Over? Authentication Coercion Keeps Evolving
Threat Research Center
Threat Research
Vulnerabilities
## You Thought It Was Over? Authentication Coercion Keeps Evolving
Bar Maor
Hila Cohen
Published: November 10, 2025
Threat Research
Vulnerabilities
Mimikatz
PrintNightmare
Privilege escalation
Windows
## Executive Summary
Imagine a scenario where malicious actors don’t need to trick you into giving up your password. They have no need to perform sophisticated social engineering attacks or exploit vulnerabilities in your operating system. Instead, they can simply force your computer to authenticate to an attacker-controlled system, effectively commanding your machine to hand over valuable credentials. This attack method is called authentication coercion.
While authentication coercion attacks such as PrintNightmare beca
Dfir Report
Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware
blogs_dfir_report·2025-05-19·CVSS 9.8
[CRITICAL] Another Confluence Bites the Dust: Falling to ELPACO-team Ransomware
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion Read More
- dragonforce Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs Read More
Services Overview
Threat Hunting
-
Integration
CTI Program Advisory
Incident Response Playbook
About us
Contact Us
Collaboration
Careers
Analysts
Access DFIR Labs
Get in Touch
Public Reports
Products Overview
Threat intel Overview
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
Detection Pack
AI Training Ground
Service Overview
Threat Hunting
Integration
CTI Program Advisory
Incident Response Playbook
Company Overview
About us
Contact Us
Careers
Analyst
SQL Brute Force Leads to BlueSky Ransomware
From OneNote to RansomNote: An Ice Col
Qualys
Steps to TruRisk™ – 2: Measure the Likelihood of Vulnerability Exploitation | Qualys
blogs_qualys·2025-04-07
Steps to TruRisk™ – 2: Measure the Likelihood of Vulnerability Exploitation | Qualys
#### Table of Contents
- Victory Belongs to the Well-Informed
- Defining the Components of Likelihood of Exploit
- The Role of CVSS, EPSS, and CISA KEV in Risk Assessment
- The Case for Context: Why Meaningful Remediation is Critical
- Qualys Vulnerability Score (QVS): A Unified Measure of Exploitability
- Qualys Detection Score (QDS): Operationalizing Risk
- Practical Evaluation of QDS vs CVSS
- From Overload to Actionable Insights
Cybersecurity programs rely on various methods to measure the risk associated with vulnerabilities for prioritization, such as CVSS, EPSS, CISA KEV, or even internally developed systems that combine multiple approaches. While these methods help assess whether a specific vulnerability exists on an asset and define its severity, traditional frameworks like CVSS
Qualys
Steps to TruRisk™ – 2: Measure the Likelihood of Vulnerability Exploitation
blogs_qualys·2025-04-07
Steps to TruRisk™ – 2: Measure the Likelihood of Vulnerability Exploitation
## Table of Contents
Victory Belongs to the Well-Informed
Defining the Components of Likelihood of Exploit
The Role of CVSS, EPSS, and CISA KEV in Risk Assessment
The Case for Context: Why Meaningful Remediation is Critical
Qualys Vulnerability Score (QVS): A Unified Measure of Exploitability
Qualys Detection Score (QDS): Operationalizing Risk
Practical Evaluation of QDS vs CVSS
From Overload to Actionable Insights
Cybersecurity programs rely on various methods to measure the risk associated with vulnerabilities for prioritization, such as CVSS, EPSS, CISA KEV, or even internally developed systems that combine multiple approaches. While these methods help assess whether a specific vulnerability exists on an asset and define its severity, traditional frameworks like CVSS often over
Tenable
From Bugs to Breaches: 25 Significant CVEs As MITRE CVE Turns 25
blogs_tenable·2024-10-22
From Bugs to Breaches: 25 Significant CVEs As MITRE CVE Turns 25
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
What Is Black Basta Ransomware and How to Mitigate Attack
blogs_qualys·2024-09-19·CVSS 5.5
[MEDIUM] What Is Black Basta Ransomware and How to Mitigate Attack
## Table of Contents
Introduction
Tools, Techniques, and Vulnerabilities Exploited
Technical Analysis
Effective Hunting Queries
Mapping MITRE ATT&CK: Key Techniques
Indicators of Compromise (IoC)
Stay to the Left of Boom of Emerging Threats
## Introduction
Black Basta is a ransomware group operating as ransomware-as-a-service (RaaS), first spotted in April 2022. It is known to use double extortion techniques where the group demands payment for the decryption and non-release of stolen data. Earlier versions of Black Basta share many similarities with Conti Ransomware.
A wide range of industries and critical infrastructure in North America, Europe, and Australia have been impacted by Black Basta. To date, 500+ organizations have been affected globally by Black Basta affiliates gain
Microsoft
Analyzing Forest Blizzard’s custom post-compromise tool for exploiting CVE-2022-38028 to obtain credentials
blogs_microsoft·2024-04-22·CVSS 8.8
[HIGH] Analyzing Forest Blizzard’s custom post-compromise tool for exploiting CVE-2022-38028 to obtain credentials
Research
April 22, 2024
Hunt for JavaScript constrained file
DeviceFileEvents
| where TimeGenerated > ago(60d) // change the duration according to your requirement
| where ActionType == "FileCreated"
| where FolderPath startswith "C:\Windows\System32\DriverStore\FileRepository\"
| where FileName endswith ".js" or FileName == "MPDW-constraints.js"
Hunt for creation of registry key / value events
DeviceRegistryEvents
| where TimeGenerated > ago(60d) // change the duration according to your requirement
| where ActionType == "RegistryValueSet"
| where RegistryKey contains "HKEY_CURRENT_USER\Software\Classes\CLSID\{026CC6D7-34B2-33D5-B551-CA31EB6CE345}\Server"
| where RegistryValueName has "(Default)"
| where RegistryValueData has "wayzgoose.dll" or RegistryValueData contains ".dll"
Hunt
Tenable
Microsoft’s March 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-21407)
blogs_tenable·2024-03-12·CVSS 8.1
[HIGH] Microsoft’s March 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-21407)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Tenable Research Advisories: Urgent Action
blogs_tenable·2023-11-20
Tenable Research Advisories: Urgent Action
by Cesar Navas November 20, 2023
Tenable Research delivers world class exposure intelligence, data science insights, zero day research and security advisories. Our Security Response Team (SRT) in Tenable Research tracks threat and vulnerability intelligence feeds to make sure our research teams can deliver sensor coverage to our products as quickly as possible. The SRT also works to dig into technical details and author white papers, blogs, and additional communications to ensure stakeholders are fully informed of the latest cyber risks and threats. The SRT provides breakdowns for the latest critical vulnerabilities on the Tenable blog.
When security events rise to the level of taking immediate action, Tenable - leveraging SRT intelligence - notifies customers proactively to provide expo
Fortinet
Ransomware Roundup - Black Basta | FortiGuard Labs
blogs_fortinet·2023-06-23
Ransomware Roundup - Black Basta | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Ransomware Roundup - Black Basta
By James Slaughter and Shunichi Imano | June 23, 2023
On a bi-weekly basis, FortiGuard Labs gathers data on ransomware variants of interest that have been gaining traction within our datasets and the OSINT community. The Ransomware Roundup report aims to provide readers with brief insights into the evolving ransomware landscape and the Fortinet solutions that protect against those variants.
This latest edition of the Ransomware Roundup covers the Black Basta ransomware.
Affected platforms: Microsoft Windows, VMWare ESXi servers
Impacted parties: Microsoft Windows and ESXi Users
Impact: Encrypts files on the compromised machine and demands ransom for file decryption
Severity level: High
Black Basta Ransomware Overview
Ov
Trendmicro
Magniber unter der Lupe
blogs_trendmicro·2023-02-02·CVSS 7.5
[HIGH] Magniber unter der Lupe
Ransomware
## Magniber unter der Lupe
Magniber-Ransomware nutzt verschiedene Schwachstellen aus, aber obwohl sie im Vergleich zu den neueren Ransomware-Kampagnen mit doppelter Erpressung eine einfachere Kill Chain verwendet, ist sie nicht weniger effektiv. Die Analyse zeigt, was zu tun ist.
By: Trend Micro Feb 02, 2023 Read time: ( words)
Save to Folio
Die Ransomware wurde bereits vor sechs Jahren entdeckt, dennoch verwenden Angreifer die Malware immer noch. Im Oktober 2022 gab es Berichte über Phishing-Attacken, über die Magniber-Ransomware verteilt wurde. Sie nutzten Standalone JavaScript-Dateien, die mit einem manipulierten Schlüssel digital signiert waren, und missbrauchten die Zero Day-Lücke CVE-2022-44698 , um Mark-of-the-Web (MOTW)-Sicherheitswarnungen zu umgehen. So konnten bö
Unit42
Vice Society: Profiling a Persistent Threat to the Education Sector
blogs_unit42·2022-12-06·CVSS 8.8
[HIGH] Vice Society: Profiling a Persistent Threat to the Education Sector
## Executive Summary
Vice Society is a ransomware gang that has been involved in high-profile activity against schools this year. Unlike many other ransomware groups such as LockBit that follow a typical ransomware-as-a-service (RaaS) model, Vice Society’s operations are different in that they’ve been known for using forks of pre-existing ransomware families in their attack chain that are sold on DarkWeb marketplaces. These include the HelloKitty (aka FiveHands) and Zeppelin strains of ransomware as opposed to Vice Society developing their own custom payload.
In September 2022, a joint Cybersecurity Advisory (CSA) from the FBI, CISA and the MS-ISAC declared they had recently observed Vice Society actors disproportionately targeting the education sector with ransomware attacks. The CSA co
Unit42
Vice Society: Profiling a Persistent Threat to the Education Sector
blogs_unit42·2022-12-06·CVSS 7.8
CVE-2021-1675 [HIGH] Vice Society: Profiling a Persistent Threat to the Education Sector
Threat Research Center
Threat Research
Ransomware
## Vice Society: Profiling a Persistent Threat to the Education Sector
JR Gumarin
Published: December 6, 2022
Ransomware
Threat Research
Vulnerabilities
CVE-2021-1675
CVE-2021-34527
HelloKitty
NGFW
PrintNightmare
Twinkling Scorpius
Vice Society
## Executive Summary
Vice Society is a ransomware gang that has been involved in high-profile activity against schools this year. Unlike many other ransomware groups such as LockBit that follow a typical ransomware-as-a-service (RaaS) model, Vice Society’s operations are different in that they’ve been known for using forks of pre-existing ransomware families in their attack chain that are sold on DarkWeb marketplaces. These include the HelloKitty (aka FiveHands) and Zeppelin stra
Sentinelone
Black Basta
blogs_sentinelone·2022-11-30
Black Basta
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Sentinelone
Vice Society
blogs_sentinelone·2022-11-30
Vice Society
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Tenable
Microsoft’s November 2022 Patch Tuesday Addresses 62 CVEs (CVE-2022-41073)
blogs_tenable·2022-11-08·CVSS 7.8
[HIGH] Microsoft’s November 2022 Patch Tuesday Addresses 62 CVEs (CVE-2022-41073)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
2021 Threat Landscape Retrospective
blogs_tenable·2022-11-07
2021 Threat Landscape Retrospective
by Cody Dumont November 7, 2022
2021 was certainly a turbulent year, punctuated with the revelation of a critical vulnerability in the widely-used Apache Log4j library. The lingering Covid-19 pandemic had already accelerated online and cloud migration, providing ripe targets for attackers. Organizations were faced with higher risks from interconnectivity resulting in major disruption from breaches, ransomware attacks, and attacks on the software supply chain. Tenable’s 2021 Threat Landscape Retrospective (TLR) provides valuable lessons learned as attackers relentlessly exploited the software supply chain. Cyber security practices need to evolve to address modern technology deployments. This dashboard leverages Tenable’s 2021 Threat Landscape Retrospective to identify the most notable cybe
Sentinelone
Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor
blogs_sentinelone·2022-11-03
Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor
## Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor
By Antonio Cocomazzi and Antonio Pirozzi
## Executive Summary
SentinelLABS researchers describe Black Basta operational TTPs in full detail, revealing previously unknown tools and techniques.
SentinelLABS assesses it is highly likely the Black Basta ransomware operation has ties with FIN7.
Black Basta maintains and deploys custom tools, including EDR evasion tools.
SentinelLABS assess it is likely the developer of these EDR evasion tools is, or was, a developer for FIN7.
Black Basta attacks use a uniquely obfuscated version of ADFind and exploit PrintNightmare, ZeroLogon and NoPac for privilege escalation.
## Overview
Black Basta ransomware emerged in April 2022 and went on a spree breach
Sentinelone
Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor
blogs_sentinelone·2022-11-03
Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor
By Antonio Cocomazzi and Antonio Pirozzi
## Executive Summary
- SentinelLABS researchers describe Black Basta operational TTPs in full detail, revealing previously unknown tools and techniques.
- SentinelLABS assesses it is highly likely the Black Basta ransomware operation has ties with FIN7.
- Black Basta maintains and deploys custom tools, including EDR evasion tools.
- SentinelLABS assess it is likely the developer of these EDR evasion tools is, or was, a developer for FIN7.
- Black Basta attacks use a uniquely obfuscated version of ADFind and exploit PrintNightmare, ZeroLogon and NoPac for privilege escalation.
## Overview
Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022. The rapidity and volume of attacks prove that the
Qualys
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
blogs_qualys·2022-08-23
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
## Table of Contents
Why Are Zero-Day Attacks/Exploits so Dangerous?
How Qualys Policy Compliance Helps Combat Zero-Day Threats
Benefit of Qualys Policy Compliance for Zero-Day Threats
Summary
Getting Started
Contributors
Zero-day vulnerability attacks have emerged as a major cybersecurity threat in the last few years. Organizations most often targeted include large enterprises and government/Federal agencies. However, any organization, regardless of its size, business, or industry, is a potential target for zero-day threats.
Most notably, already publicly disclosed. This means that one out of every four zero-day exploits detected could potentially have been avoided if a more thorough investigation and patching effort had been pursued. In 2021, around 58 zero-day vulnerabilities we
Tenable
Cybersecurity Snapshot: 6 Things That Matter Right Now
blogs_tenable·2022-08-19
Cybersecurity Snapshot: 6 Things That Matter Right Now
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft’s August 2022 Patch Tuesday Addresses 118 CVEs (CVE-2022-34713)
blogs_tenable·2022-08-09·CVSS 7.8
[HIGH] Microsoft’s August 2022 Patch Tuesday Addresses 118 CVEs (CVE-2022-34713)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Analyzing the Vulnerabilities Associated with the Top Malware Strains of 2021
blogs_tenable·2022-08-04
Analyzing the Vulnerabilities Associated with the Top Malware Strains of 2021
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
blogs_trendmicro·2022-06-30·CVSS 8.8
[HIGH] Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
Ransomware
# Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
We look into a recent attack orchestrated by the Black Basta ransomware group that used the banking trojan QakBot as a means of entry and movement and took advantage of the PrintNightmare vulnerability to perform privileged file operations.
By: Kenneth Adrian Apostol, Paolo Ronniel Labrador, Mirah Manlapig, James Panlilio, Emmanuel Panopio, John Kenneth Reyes, Melvin Singwa
2022/06/30
Read time: ( words)
Save to Folio
Since it became operational in April, Black Basta has garnered notoriety for its recent attacks on 50 organizations around the world and its use of double extortion, a modern ransomware tactic in which attackers encrypt confidential data and threaten t
Trendmicro
Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
blogs_trendmicro·2022-06-30·CVSS 8.8
[HIGH] Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
Ransomware
# Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
We look into a recent attack orchestrated by the Black Basta ransomware group that used the banking trojan QakBot as a means of entry and movement and took advantage of the PrintNightmare vulnerability to perform privileged file operations.
By: Kenneth Adrian Apostol, Paolo Ronniel Labrador, Mirah Manlapig, James Panlilio, Emmanuel Panopio, John Kenneth Reyes, Melvin Singwa
Jun 30, 2022
Read time: ( words)
Save to Folio
Since it became operational in April, Black Basta has garnered notoriety for its recent attacks on 50 organizations around the world and its use of double extortion, a modern ransomware tactic in which attackers encrypt confidential data and threaten
Trendmicro
Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
blogs_trendmicro·2022-06-30·CVSS 8.8
[HIGH] Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
Ransomware
## Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
We look into a recent attack orchestrated by the Black Basta ransomware group that used the banking trojan QakBot as a means of entry and movement and took advantage of the PrintNightmare vulnerability to perform privileged file operations.
By: Kenneth Adrian Apostol, Paolo Ronniel Labrador, Mirah Manlapig, James Panlilio, Emmanuel Panopio, John Kenneth Reyes, Melvin Singwa Jun 30, 2022 Read time: ( words)
Save to Folio
Since it became operational in April, Black Basta has garnered notoriety for its recent attacks on 50 organizations around the world and its use of double extortion , a modern ransomware tactic in which attackers encrypt confidential data and threate
Trendmicro
Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
blogs_trendmicro·2022-06-30·CVSS 8.8
[HIGH] Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
Ransomware
## Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
We look into a recent attack orchestrated by the Black Basta ransomware group that used the banking trojan QakBot as a means of entry and movement and took advantage of the PrintNightmare vulnerability to perform privileged file operations.
By: Kenneth Adrian Apostol, Paolo Ronniel Labrador, Mirah Manlapig, James Panlilio, Emmanuel Panopio, John Kenneth Reyes, Melvin Singwa 2022/06/30 Read time: ( words)
Save to Folio
Since it became operational in April, Black Basta has garnered notoriety for its recent attacks on 50 organizations around the world and its use of double extortion , a modern ransomware tactic in which attackers encrypt confidential data and threaten
Qualys
Ransomware Insights from the FBI’s 2021 Internet Crime Report | Qualys
blogs_qualys·2022-05-04
Ransomware Insights from the FBI’s 2021 Internet Crime Report | Qualys
#### Table of Contents
- Top Ransomware Attack Vectors of 2021
- How Can Qualys Help?
The FBI has published its annual report on Internet crime. Qualys has analyzed its trends and statistics. In this post, we review our findings, especially with regards to the prevalence of Ransomware, and our recommendations for actions that enterprises should take to mitigate their risk.
Every year the U.S. Federal Bureau of Investigation publishes an Internet crime report which summarizes its insights on trends and threats from cybercriminals based on all cybercrimes reported to the FBI by the American public. This annual report provides fascinating insights into the threat landscape, key trends, statistics on types of crimes, the real losses resulting from them, and perhaps most importantly, key ins
Qualys
Ransomware Insights from the FBI’s 2021 Internet Crime Report
blogs_qualys·2022-05-04
Ransomware Insights from the FBI’s 2021 Internet Crime Report
## Table of Contents
Top Ransomware Attack Vectors of 2021
How Can Qualys Help?
The FBI has published its annual report on Internet crime. Qualys has analyzed its trends and statistics. In this post, we review our findings, especially with regards to the prevalence of Ransomware, and our recommendations for actions that enterprises should take to mitigate their risk.
Every year the U.S. Federal Bureau of Investigation publishes an Internet crime report which summarizes its insights on trends and threats from cybercriminals based on all cybercrimes reported to the FBI by the American public. This annual report provides fascinating insights into the threat landscape, key trends, statistics on types of crimes, the real losses resulting from them, and perhaps most importantly, key insights
Tenable
ContiLeaks: Chats Reveal Over 30 Vulnerabilities Used by Conti Ransomware – How Tenable Can Help
blogs_tenable·2022-03-24
ContiLeaks: Chats Reveal Over 30 Vulnerabilities Used by Conti Ransomware – How Tenable Can Help
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
21st March – Threat Intelligence Report
blogs_checkpoint·2022-03-21
CVE-2022-0811 21st March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 21st March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 21st March, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research has found sensitive data of a number of mobile applications exposed and available to anyone. By searching VirusTotal, CPR found 2113 mobile applications whose databases were unprotected and exposed throughout the course of a three month research study.
Check Point CloudGuard for Application Security prov
Tenable
Behind the Scenes: How We Picked 2021’s Top Vulnerabilities – and What We Left Out
blogs_tenable·2022-03-11
Behind the Scenes: How We Picked 2021’s Top Vulnerabilities – and What We Left Out
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Tenable
Microsoft’s February 2022 Patch Tuesday Addresses 48 CVEs (CVE-2022-21989)
blogs_tenable·2022-02-08·CVSS 7.8
[HIGH] Microsoft’s February 2022 Patch Tuesday Addresses 48 CVEs (CVE-2022-21989)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
Attack techniques observed by Kaspersky MDR
blogs_securelist·2021-12-15·CVSS 7.8
[HIGH] Attack techniques observed by Kaspersky MDR
Table of Contents
- PrintNightmare vulnerability exploitation
- MuddyWater attack
- Credential Dumping from LSASS Memory
- Conclusion
Authors
- Petr Mareichev
- Sergey Soldatov
Kaspersky Managed Detection and Response (MDR) provides advanced protection against the growing number of threats that bypass automatic security barriers. Its capabilities are backed by a high-professional team of security analysts operating all over the world. Each suspicious security event is validated by our analysts complementing the automatic detection logic and letting us continuously improve the detection rules.
The MDR results allow us to map out the modern threat landscape and show techniques used by attackers right now. We share these results with you so that you are more informed about in-the-wild a
Securelist
Kaspersky Managed Detection and Response: interesting cases
blogs_securelist·2021-12-15·CVSS 7.8
[HIGH] Kaspersky Managed Detection and Response: interesting cases
Table of Contents
PrintNightmare vulnerability exploitation
Case #1
Case #2
MuddyWater attack
Credential Dumping from LSASS Memory
Conclusion
Authors
Petr Mareichev
Sergey Soldatov
Kaspersky Managed Detection and Response (MDR) provides advanced protection against the growing number of threats that bypass automatic security barriers. Its capabilities are backed by a high-professional team of security analysts operating all over the world. Each suspicious security event is validated by our analysts complementing the automatic detection logic and letting us continuously improve the detection rules.
The MDR results allow us to map out the modern threat landscape and show techniques used by attackers right now. We share these results with you so that you are more informed about in-t
Securelist
IT threat evolution Q3 2021
blogs_securelist·2021-11-26
IT threat evolution Q3 2021
Table of Contents
- Targeted attacks
- Other malware
Authors
- David Emm
- IT threat evolution Q3 2021
- IT threat evolution in Q3 2021. PC statistics
- IT threat evolution in Q3 2021. Mobile statistics
## Targeted attacks
### WildPressure targets macOS
Last March, we reported a WildPressure campaign targeting industrial-related entities in the Middle East. While tracking this threat actor in spring 2021, we discovered a newer version. It contains the C++ Milum Trojan, a corresponding VBScript variant and a set of modules that include an orchestrator and three plugins. This confirms our previous assumption that there were more last-stagers besides the C++ ones.
Another language used by WildPressure is Python. The PyInstaller module for Windows contains a script named “Guard”. Inter
Securelist
IT threat evolution in Q3 2021. PC statistics
blogs_securelist·2021-11-26
IT threat evolution in Q3 2021. PC statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Ransomware programs
Quarterly trends and highlights
Attack on Kaseya and the REvil story
The arrival of BlackMatter: DarkSide restored?
Q3 closures
Exploitation of vulnerabilities and new attack methods
Number of new ransomware modifications
Number of users attacked by ransomware Trojans
Geography of ransomware attacks
Top 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by cybercriminals during cyberattacks
Quarter highlights
Statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
Countries tha
Securelist
IT threat evolution in Q3 2021. PC statistics
blogs_securelist·2021-11-26
IT threat evolution in Q3 2021. PC statistics
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Number of users attacked by ransomware Trojans
- Geography of ransomware attacks
- Top 10 most common families of ransomware Trojans
- Miners
- Vulnerable applications used by cybercriminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution Q3 2021
- IT threat evolution in Q3 2021. PC statistics
- IT threat evolution in Q3 2021. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q3 2021:
- Kaspersky solutions blocked 1,098,968,315 attacks from online reso
Securelist
IT threat evolution Q3 2021
blogs_securelist·2021-11-26·CVSS 8.8
CVE-2021-40444 [HIGH] IT threat evolution Q3 2021
Table of Contents
Targeted attacks
WildPressure targets macOS
LuminousMoth: sweeping attacks for the chosen few
Targeted attacks exploiting CVE-2021-40444
Tomiris backdoor linked to SolarWinds attack
GhostEmperor
FinSpy: analysis of current capabilities
Other malware
REvil attack on MSPs and their customers worldwide
What a [Print]Nightmare
Grandoreiro and Melcoz arrests
Gamers beware
Triada Trojan in WhatsApp mod
Qakbot banking Trojan
Authors
David Emm
IT threat evolution Q3 2021
IT threat evolution in Q3 2021. PC statistics
IT threat evolution in Q3 2021. Mobile statistics
## Targeted attacks
## WildPressure targets macOS
Last March, we reported a WildPressure campaign targeting industrial-related entities in the Middle East . While tracking this threat actor in spr
Qualys
Conti Ransomware | Qualys
blogs_qualys·2021-11-18·CVSS 8.8
[HIGH] Conti Ransomware | Qualys
#### Table of Contents
- Technical Details:
- Modes of Operation
- The Ransom Note:
- IoC:
- TTP Map:
- Summary
Conti is a sophisticated Ransomware-as-a-Service (RaaS) model first detected in December 2019. Since its inception, its use has grown rapidly and has even displaced the use of other RaaS tools like Ryuk. The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) issued a warning about Conti in Sept 2021, noting that they had observed it being used in more than 400 cyberattacks globally, though concentrated in North America and Europe.
The most common initial infection vectors used are spear phishing and RDP (Remote Desktop Protocol) services. Phishing emails work either through malicious attachments, such as Word documents with an
Qualys
Conti Ransomware
blogs_qualys·2021-11-18·CVSS 8.8
[HIGH] Conti Ransomware
## Table of Contents
Technical Details:
Modes of Operation
The Ransom Note:
IoC:
TTP Map:
Summary
Conti is a sophisticated Ransomware-as-a-Service (RaaS) model first detected in December 2019. Since its inception, its use has grown rapidly and has even displaced the use of other RaaS tools like Ryuk. The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) issued a warning about Conti in Sept 2021, noting that they had observed it being used in more than 400 cyberattacks globally, though concentrated in North America and Europe.
The most common initial infection vectors used are spear phishing and RDP (Remote Desktop Protocol) services. Phishing emails work either through malicious attachments, such as Word documents with an embedded
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01
## Table of Contents
Overview
Directive Scope
CISA Catalog of Known Exploited Vulnerabilities
Detect CISAs Vulnerabilities Using Qualys VMDR
Remediation
Federal Enterprises and Agencies Can Act Now
Summary
Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01 , “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to remediate
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
#### Table of Contents
- Overview
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISAs Vulnerabilities Using Qualys VMDR
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01, “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to
Tenable
Active Directory is Now in the Ransomware Crosshairs
blogs_tenable·2021-10-28
Active Directory is Now in the Ransomware Crosshairs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft’s October 2021 Patch Tuesday Addresses 74 CVEs (CVE-2021-40449)
blogs_tenable·2021-10-12·CVSS 7.8
[HIGH] Microsoft’s October 2021 Patch Tuesday Addresses 74 CVEs (CVE-2021-40449)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
The Rise of Ransomware
blogs_qualys·2021-10-05
The Rise of Ransomware
## Table of Contents
Ransomware Infection Vectors
Ransomware Attacks and Exact CVEs To Prioritize for Monitoring
Unified View of Critical Ransomware Risk Exposures
Qualys Ransomware Risk Assessment & Remediation Service
Continuous detection & prioritization for Ransomware-specific vulnerabilities withVMDR
DiscoverandPrioritizeRansomware Vulnerabilities
Discover and Mitigate RansomwareMisconfigurationssuch as SMB, Insecure RDP
Automated Proactive & Reactive Patching for Ransomware vulnerabilities
Ready to Learn more and see for yourself?
Resources
References
With most employees still working from remote locations, ransomware attacks have increased steadily since the early months of the Covid-19 pandemic. According to the FBI’s 2020 Internet Crime Report 2400+ ransomware-related
Qualys
Assess Your Risk From Ransomware Attacks, Powered by Qualys Research | Qualys
blogs_qualys·2021-10-05
Assess Your Risk From Ransomware Attacks, Powered by Qualys Research | Qualys
#### Table of Contents
- Clear guidelines from authorities for ransomware prevention
- Qualys undertakes research on ransomware to deliver actionable insights
- Challenges in following guidelines for preventing ransomware attacks
- Assess & continuously monitor your ransomware risk, powered by Qualys Research
- Learn more and see for yourself
- Resources
- References
Ransomware attacks are among the most significant cyber threats facing businesses today. Recent warnings about Conti ransomware, issued by a joint cybersecurity advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), FBI and National Security Agency, are a strong signal that ransomware attacks are becoming even more sophisticated and massive via the ransomware-as-a-service operating model. This new mo
Qualys
Assess Your Risk From Ransomware Attacks, Powered by Qualys Research
blogs_qualys·2021-10-05
Assess Your Risk From Ransomware Attacks, Powered by Qualys Research
## Table of Contents
Clear guidelines from authorities for ransomware prevention
Qualys undertakes research on ransomware to deliver actionable insights
Challenges in following guidelines for preventing ransomware attacks
Assess & continuously monitor your ransomware risk, powered by Qualys Research
Learn more and see for yourself
Resources
References
Ransomware attacks are among the most significant cyber threats facing businesses today. Recent warnings about Conti ransomware, issued by a joint cybersecurity advisory from the U.S. Cybersecurity and Infrastructure Security Agency (CISA), FBI and National Security Agency, are a strong signal that ransomware attacks are becoming even more sophisticated and massive via the ransomware-as-a-service operating model. This new model allows
Tenable
Microsoft’s September 2021 Patch Tuesday Addresses 60 CVEs (CVE-2021-40444)
blogs_tenable·2021-09-14·CVSS 8.8
[HIGH] Microsoft’s September 2021 Patch Tuesday Addresses 60 CVEs (CVE-2021-40444)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Threat Source newsletter (Aug. 19, 2021)
blogs_talos·2021-08-19
Threat Source newsletter (Aug. 19, 2021)
Good afternoon, Talos readers.
I'm writing this on Tuesday morning on account of vacation (again), so apologies if we miss any major stories.
You certainly don't want to miss our latest blog post on the Neurevt remote access trojan that's targeting users in Mexico. This malware is mainly designed to steal login credentials to banking websites, and we don't really need to tell you why that would be bad.
## Upcoming Talos public engagements
CTIR on the Technado podcast
Speaker: Chris DiSalle
Date: Sept. 9
Location: Virtual
Description: Chris DiSalle from Talos Incident Response will join the Technado podcast to share the ins and outs of the IR industry. Chris will talk to host Don Pezet about how he got started in incident response, horror stories he's seen in the field, and much mor
Talos
Threat Source newsletter (Aug. 19, 2021)
blogs_talos·2021-08-19
Threat Source newsletter (Aug. 19, 2021)
## Threat Source newsletter (Aug. 19, 2021)
Good afternoon, Talos readers.
I'm writing this on Tuesday morning on account of vacation (again), so apologies if we miss any major stories.
You certainly don't want to miss our latest blog post on the Neurevt remote access trojan that's targeting users in Mexico. This malware is mainly designed to steal login credentials to banking websites, and we don't really need to tell you why that would be bad.
## Upcoming Talos public engagements
CTIR on the Technado podcast
Speaker: Chris DiSalle
Date: Sept. 9
Location: Virtual
Description: Chris DiSalle from Talos Incident Response will join the Technado podcast to share the ins and outs of the IR industry. Chris will talk to host Don Pezet about how he got started in incident response, horror
Tenable
The PrintNightmare Continues: Another Zero-Day in Print Spooler Awaits Patch (CVE-2021-36958)
blogs_tenable·2021-08-19·CVSS 7.8
[HIGH] The PrintNightmare Continues: Another Zero-Day in Print Spooler Awaits Patch (CVE-2021-36958)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Detecting PrintNightmare Exploit Attempts using Trend Micro Vision One and Cloud One
blogs_trendmicro·2021-08-12·CVSS 7.8
[HIGH] Detecting PrintNightmare Exploit Attempts using Trend Micro Vision One and Cloud One
## Detecting PrintNightmare Exploit Attempts using Trend Micro Vision One and Cloud One
We look into the different implementations of PrintNightmare and include recommendations on how security teams can safeguard their workloads.
By: Trend Micro Aug 12, 2021 Read time: ( words)
Save to Folio
Update as of August 18, 2:54 a.m. EDT: We updated the section "Trend Micro Vision One™ Hunting Queries" (search queries) to include the latest indicators. Specifically, Figures 21 and 25 address events for the latest PrintNightmare implementation under CVE-2021-36958.
PrintNightmare is one of the latest set of exploits abused for the Print Spooler vulnerabilities that have been identified as CVE-2021-1675 , CVE-2021-34527 , CVE-2021-34481 , and CVE-2021-36958 . It is a code execution vulnerability
Trendmicro
Detecting PrintNightmare Exploit Attempts using Trend Micro Vision One and Cloud One
blogs_trendmicro·2021-08-12·CVSS 7.8
[HIGH] Detecting PrintNightmare Exploit Attempts using Trend Micro Vision One and Cloud One
## Detecting PrintNightmare Exploit Attempts using Trend Micro Vision One and Cloud One
We look into the different implementations of PrintNightmare and include recommendations on how security teams can safeguard their workloads.
By: Trend Micro 2021/08/12 Read time: ( words)
Save to Folio
Update as of August 18, 2:54 a.m. EDT: We updated the section "Trend Micro Vision One™ Hunting Queries" (search queries) to include the latest indicators. Specifically, Figures 21 and 25 address events for the latest PrintNightmare implementation under CVE-2021-36958.
PrintNightmare is one of the latest set of exploits abused for the Print Spooler vulnerabilities that have been identified as CVE-2021-1675 , CVE-2021-34527 , CVE-2021-34481 , and CVE-2021-36958 . It is a code execution vulnerability (
Trendmicro
Detecting PrintNightmare Exploit Attempts using Trend Micro Vision One and Cloud One
blogs_trendmicro·2021-08-12·CVSS 7.8
[HIGH] Detecting PrintNightmare Exploit Attempts using Trend Micro Vision One and Cloud One
# Detecting PrintNightmare Exploit Attempts using Trend Micro Vision One and Cloud One
We look into the different implementations of PrintNightmare and include recommendations on how security teams can safeguard their workloads.
By: Trend Micro
2021/08/12
Read time: ( words)
Save to Folio
Update as of August 18, 2:54 a.m. EDT: We updated the section "Trend Micro Vision One™ Hunting Queries" (search queries) to include the latest indicators. Specifically, Figures 21 and 25 address events for the latest PrintNightmare implementation under CVE-2021-36958.
PrintNightmare is one of the latest set of exploits abused for the Print Spooler vulnerabilities that have been identified as CVE-2021-1675, CVE-2021-34527, CVE-2021-34481, and CVE-2021-36958. It is a code execution vulnerability (both
Securelist
IT threat evolution in Q2 2021. PC statistics
blogs_securelist·2021-08-12
IT threat evolution in Q2 2021. PC statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Ransomware programs
Quarterly trends and highlights
Attack on Colonial Pipeline and closure of DarkSide
Closure of Avaddon
Clash with Clop
Attacks on NAS devices
Number of new ransomware modifications
Number of users attacked by ransomware Trojans
Geography of ransomware attacks
Top 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by cybercriminals during cyberattacks
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
Countries that serve as sources of web-based attacks: Top 10
Countries where users fa
Talos
Vice Society leverages PrintNightmare in ransomware attacks
blogs_talos·2021-08-12·CVSS 7.8
CVE-2021-1675 [HIGH] Vice Society leverages PrintNightmare in ransomware attacks
## Executive Summary
Another threat actor is actively exploiting the so-called PrintNightmarevulnerability (CVE-2021-1675 / CVE-2021-34527) in Windows' print spooler service to spread laterally across a victim's network as part of a recent ransomware attack, according to Cisco Talos Incident Response research. While previous research found that other threat actors had been exploiting this vulnerability, this appears to be new for the threat actor Vice Society.
Talos Incident Response's research demonstrates that multiple, distinct threat actors view this vulnerability as attractive to use during their attacks and may indicate that this vulnerability will continue to see more widespread adoption and incorporation by various adversaries moving forward. For defenders, it is important to und
Trendmicro
Detecting PrintNightmare Exploit Attempts using Trend Micro Vision One and Cloud One
blogs_trendmicro·2021-08-12·CVSS 7.8
[HIGH] Detecting PrintNightmare Exploit Attempts using Trend Micro Vision One and Cloud One
## Detecting PrintNightmare Exploit Attempts using Trend Micro Vision One and Cloud One
We look into the different implementations of PrintNightmare and include recommendations on how security teams can safeguard their workloads.
By: Trend Micro Aug 12, 2021 Read time: ( words)
Save to Folio
Update as of 18 August, 2:54 a.m. EDT: We updated the section "Trend Micro Vision One™ Hunting Queries" (search queries) to include the latest indicators. Specifically, Figures 21 and 25 address events for the latest PrintNightmare implementation under CVE-2021-36958.
PrintNightmare is one of the latest set of exploits abused for the Print Spooler vulnerabilities that have been identified as CVE-2021-1675 , CVE-2021-34527 , CVE-2021-34481 , and CVE-2021-36958 . It is a code execution vulnerability
Talos
Vice Society leverages PrintNightmare in ransomware attacks
blogs_talos·2021-08-12·CVSS 7.8
CVE-2021-1675 [HIGH] Vice Society leverages PrintNightmare in ransomware attacks
## Vice Society leverages PrintNightmare in ransomware attacks
## Executive Summary
Another threat actor is actively exploiting the so-called PrintNightmare vulnerability (CVE-2021-1675 / CVE-2021-34527) in Windows' print spooler service to spread laterally across a victim's network as part of a recent ransomware attack, according to Cisco Talos Incident Response research. While previous research found that other threat actors had been exploiting this vulnerability , this appears to be new for the threat actor Vice Society.
Talos Incident Response's research demonstrates that multiple, distinct threat actors view this vulnerability as attractive to use during their attacks and may indicate that this vulnerability will continue to see more widespread adoption and incorporation by various
Securelist
IT threat evolution in Q2 2021. PC statistics
blogs_securelist·2021-08-12
IT threat evolution in Q2 2021. PC statistics
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by cybercriminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
These statistics are based on detection verdicts of Kaspersky products received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q2 2021:
- Kaspersky solutions blocked 1,686,025,551 attacks from online resources across the globe.
- Web antivirus recognized 675,832,360 unique URLs as malicious.
- Attempts to run malware for stealing money from online bank accounts were stopped on the computers of 119,252 unique users.
- Ransomware attacks were defeated on the computers
Fortinet
The Affiliate’s Cookbook - A Firsthand Peek into the Operations and Tradecraft of Conti
blogs_fortinet·2021-08-10
The Affiliate’s Cookbook - A Firsthand Peek into the Operations and Tradecraft of Conti
FORTIGUARD LABS THREAT RESEARCH
The Affiliate’s Cookbook - A Firsthand Peek into the Operations and Tradecraft of Conti
By Val Saengphaibul | August 10, 2021
FortiGuard Labs Threat Research Report
Ransomware has dominated the media headlines for the first half of 2021. The attack on Colonial Pipeline (Darkside) caused a disruption in the distribution of oil and gasoline across the East coast on the United States (ironically, it was the billing system taken offline and not OT devices controlling the supply). The one on JBS Foods in Brazil (REvil) led to concerns about a potential global meat shortage. And the one that targeted managed service provider Kaseya VSA (REvil) was a supply chain attack which resulted in downstream customers being impacted with ransomware attacks.
Prior to thes
Tenable
Microsoft’s August 2021 Patch Tuesday Addresses 44 CVEs (CVE-2021-26424, CVE-2021-36948)
blogs_tenable·2021-08-10·CVSS 9.9
[CRITICAL] Microsoft’s August 2021 Patch Tuesday Addresses 44 CVEs (CVE-2021-26424, CVE-2021-36948)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
09th August – Threat Intelligence Report
blogs_checkpoint·2021-08-09·CVSS 9.8
CVE-2021-20090 [CRITICAL] 09th August – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 09th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 9th August, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Four critical infrastructures organizations in South East Asia have been the target the of a cyberespionage campaign by alleged Chinese threat actors for several months, aiming at exploiting information from the victims’ SCADA systems. The targeted sectors included power, water, defense, and communications companies.
The Au
Unit42
Threat Brief: Windows Print Spooler RCE Vulnerability (CVE-2021-34527 AKA PrintNightmare)
blogs_unit42·2021-07-14·CVSS 7.8
CVE-2021-34527 [HIGH] Threat Brief: Windows Print Spooler RCE Vulnerability (CVE-2021-34527 AKA PrintNightmare)
## Executive Summary
On July 1, 2021, Microsoft released a security advisory for a new remote code execution (RCE) vulnerability in Windows, CVE-2021-34527, referred to publicly as "PrintNightmare.” Security researchers initially believed this vulnerability to be tied to CVE-2021-1675 (Windows Print Spooler Remote Code Execution Vulnerability), which was first disclosed in the Microsoft Patch Tuesday release on June 8, 2021. Microsoft has since updated the FAQ section of the advisory that shows CVE-2021-34527 is similar but distinct from CVE-2021-1675, which addresses a different but related vulnerability in RpcAddPrinterDriverEx().
## Systems Vulnerable to CVE-2021-34527
All Windows versions are affected by this vulnerability. Domain controllers, clients and member servers running the
Unit42
Threat Brief: Windows Print Spooler RCE Vulnerability (CVE-2021-34527 AKA PrintNightmare)
blogs_unit42·2021-07-14·CVSS 7.8
CVE-2021-34527 [HIGH] Threat Brief: Windows Print Spooler RCE Vulnerability (CVE-2021-34527 AKA PrintNightmare)
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: Windows Print Spooler RCE Vulnerability (CVE-2021-34527 AKA PrintNightmare)
Unit 42
Published: July 14, 2021
High Profile Threats
Vulnerabilities
CVE-2021-1675
CVE-2021-34527
PrintNightmare
Remote Code Execution
Windows
## Executive Summary
On July 1, 2021, Microsoft released a security advisory for a new remote code execution (RCE) vulnerability in Windows, CVE-2021-34527, referred to publicly as "PrintNightmare.” Security researchers initially believed this vulnerability to be tied to CVE-2021-1675 (Windows Print Spooler Remote Code Execution Vulnerability), which was first disclosed in the Microsoft Patch Tuesday release on June 8, 2021. Microsoft has since updated the FAQ section of the advis
Sentinelone
PrintNightmare Vulnerability: Analysis and Mitigation
blogs_sentinelone·2021-07-14·CVSS 7.8
CVE-2021-34527 [HIGH] PrintNightmare Vulnerability: Analysis and Mitigation
## Executive Summary
- A remote code execution vulnerability is being dubbed ‘PrintNightmare’ (CVE-2021-34527 and CVE-2021-1675).
- The vulnerabilities are present in the Windows Spooler Service present on all Windows versions.
- Microsoft has released two patches to address these vulnerabilities (an Out-of_Band update on July 1 as well as the July 13th monthly update).
- Exploit code is readily available and has already been folded into popular hacking tools like Mimikatz and the Metasploit framework.
- SentinelOne has provided DeepVisibility queries to detect attempts to exploit PrintNightmare in customer environments.
## What Happened?
On June 29, 2021, details emerged of a remotely exploitable vulnerability in the Microsoft Windows Print Spooler service affecting all versions of Win
Sentinelone
PrintNightmare Vulnerability: Analysis and Mitigation
blogs_sentinelone·2021-07-14·CVSS 7.8
CVE-2021-34527 [HIGH] PrintNightmare Vulnerability: Analysis and Mitigation
## Executive Summary
A remote code execution vulnerability is being dubbed ‘PrintNightmare’ (CVE-2021-34527 and CVE-2021-1675).
The vulnerabilities are present in the Windows Spooler Service present on all Windows versions.
Microsoft has released two patches to address these vulnerabilities (an Out-of_Band update on July 1 as well as the July 13th monthly update).
Exploit code is readily available and has already been folded into popular hacking tools like Mimikatz and the Metasploit framework.
SentinelOne has provided DeepVisibility queries to detect attempts to exploit PrintNightmare in customer environments.
## What Happened?
On June 29, 2021, details emerged of a remotely exploitable vulnerability in the Microsoft Windows Print Spooler service affecting all versions of Windows t
Tenable
PrintNightmare
blogs_tenable·2021-07-13·CVSS 7.8
CVE-2021-34527 [HIGH] PrintNightmare
by Cody Dumont July 13, 2021
On July 6, Microsoft updated its advisory to announce the availability of out-of-band patches for a critical vulnerability in its Windows Print Spooler that researchers are calling PrintNightmare. Microsoft originally released its advisory for CVE-2021-34527 on July 1. This advisory was released in response to public reports about a proof-of-concept (PoC) exploit for CVE-2021-1675, a similar vulnerability in the Windows Print Spooler. To help clear up confusion about the vulnerability, Microsoft updated its advisory for CVE-2021-1675 to clarify that it is “similar but distinct from CVE-2021-34527.” This remote code execution (RCE) vulnerability affects all versions of Microsoft Windows.
CVE-2021-34527 is an RCE vulnerability in the Windows Print Spooler Servi
Trendmicro
July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
blogs_trendmicro·2021-07-13·CVSS 9.1
[CRITICAL] July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
Exploits & Vulnerabilities
# July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
After two relatively quiet months, July has proven to be another busy month for Microsoft security bulletins. A total of 117 bulletins were issued for various security vulnerabilities fixed in the July Patch Tuesday cycle.
By: Trend Micro
2021/07/13
Read time: ( words)
Save to Folio
After two relatively quiet months, July has proven to be another busy month for Microsoft security bulletins. A total of 117 bulletins were issued for various security vulnerabilities fixed in the July Patch Tuesday cycle. Thirteen of these were rated as Critical, 103 as Important, and one was classified as Moderate. Fifteen were submitted via the Trend Micro Zero Day Initiative.
PrintNightmare pat
Qualys
Microsoft and Adobe Patch Tuesday (July 2021) – Microsoft 117 Vulnerabilities with 13 Critical, Adobe 26 Vulnerabilities | Qualys
blogs_qualys·2021-07-13·CVSS 7.8
CVE-2021-34448 [HIGH] Microsoft and Adobe Patch Tuesday (July 2021) – Microsoft 117 Vulnerabilities with 13 Critical, Adobe 26 Vulnerabilities | Qualys
### Microsoft Patch Tuesday – July 2021
Microsoft patched 117 vulnerabilities in their July 2021 Patch Tuesday release, and 13 of them are rated as critical severity.
### Critical Microsoft Vulnerabilities Patched
CVE-2021-34448 – Scripting Engine Memory Corruption Vulnerability
This is being actively exploited. The vulnerability allows an attacker to execute malicious code on a compromised website if a user browses to a specially crafted file on the website. The vendor has assigned a CVSSv3 base score of 6.8 and should be prioritized for patching.
CVE-2021-34494 – Windows DNS Server Remote Code Execution Vulnerability
Microsoft released patches addressing a critical RCE vulnerability in Windows DNS Server (CVE-2021-34494). This CVE has a high likelihood of exploitability and is assi
Trendmicro
July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
blogs_trendmicro·2021-07-13·CVSS 9.1
[CRITICAL] July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
Exploits & Vulnerabilities
## July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
After two relatively quiet months, July has proven to be another busy month for Microsoft security bulletins. A total of 117 bulletins were issued for various security vulnerabilities fixed in the July Patch Tuesday cycle.
By: Trend Micro 2021/07/13 Read time: ( words)
Save to Folio
After two relatively quiet months, July has proven to be another busy month for Microsoft security bulletins. A total of 117 bulletins were issued for various security vulnerabilities fixed in the July Patch Tuesday cycle. Thirteen of these were rated as Critical, 103 as Important, and one was classified as Moderate. Fifteen were submitted via the Trend Micro Zero Day Initiative .
PrintNightmare pa
Trendmicro
July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
blogs_trendmicro·2021-07-13·CVSS 9.1
[CRITICAL] July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
Exploits & Vulnerabilities
## July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
After two relatively quiet months, July has proven to be another busy month for Microsoft security bulletins. A total of 117 bulletins were issued for various security vulnerabilities fixed in the July Patch Tuesday cycle.
By: Trend Micro Jul 13, 2021 Read time: ( words)
Save to Folio
After two relatively quiet months, July has proven to be another busy month for Microsoft security bulletins. A total of 117 bulletins were issued for various security vulnerabilities fixed in the July Patch Tuesday cycle. Thirteen of these were rated as Critical, 103 as Important, and one was classified as Moderate. Fifteen were submitted via the Trend Micro Zero Day Initiative .
PrintNightmare
Trendmicro
July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
blogs_trendmicro·2021-07-13·CVSS 9.1
[CRITICAL] July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
Exploits y vulnerabilidades
## July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
After two relatively quiet months, July has proven to be another busy month for Microsoft security bulletins. A total of 117 bulletins were issued for various security vulnerabilities fixed in the July Patch Tuesday cycle.
By: Trend Micro Jul 13, 2021 Read time: ( words)
Save to Folio
After two relatively quiet months, July has proven to be another busy month for Microsoft security bulletins. A total of 117 bulletins were issued for various security vulnerabilities fixed in the July Patch Tuesday cycle. Thirteen of these were rated as Critical, 103 as Important, and one was classified as Moderate. Fifteen were submitted via the Trend Micro Zero Day Initiative .
PrintNightmare
Trendmicro
July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
blogs_trendmicro·2021-07-13·CVSS 9.1
[CRITICAL] July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
Sfruttamento vulnerabilità
## July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
After two relatively quiet months, July has proven to be another busy month for Microsoft security bulletins. A total of 117 bulletins were issued for various security vulnerabilities fixed in the July Patch Tuesday cycle.
By: Trend Micro Jul 13, 2021 Read time: ( words)
Save to Folio
After two relatively quiet months, July has proven to be another busy month for Microsoft security bulletins. A total of 117 bulletins were issued for various security vulnerabilities fixed in the July Patch Tuesday cycle. Thirteen of these were rated as Critical, 103 as Important, and one was classified as Moderate. Fifteen were submitted via the Trend Micro Zero Day Initiative .
PrintNightmare
Trendmicro
July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
blogs_trendmicro·2021-07-13·CVSS 9.1
[CRITICAL] July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
Ausnutzung von Schwachstellen
## July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
After two relatively quiet months, July has proven to be another busy month for Microsoft security bulletins. A total of 117 bulletins were issued for various security vulnerabilities fixed in the July Patch Tuesday cycle.
By: Trend Micro Jul 13, 2021 Read time: ( words)
Save to Folio
After two relatively quiet months, July has proven to be another busy month for Microsoft security bulletins. A total of 117 bulletins were issued for various security vulnerabilities fixed in the July Patch Tuesday cycle. Thirteen of these were rated as Critical, 103 as Important, and one was classified as Moderate. Fifteen were submitted via the Trend Micro Zero Day Initiative .
PrintNightma
Qualys
Microsoft and Adobe Patch Tuesday (July 2021) – Microsoft 117 Vulnerabilities with 13 Critical, Adobe 26 Vulnerabilities
blogs_qualys·2021-07-13·CVSS 7.8
CVE-2021-34448 [HIGH] Microsoft and Adobe Patch Tuesday (July 2021) – Microsoft 117 Vulnerabilities with 13 Critical, Adobe 26 Vulnerabilities
## Microsoft Patch Tuesday – July 2021
Microsoft patched 117 vulnerabilities in their July 2021 Patch Tuesday release, and 13 of them are rated as critical severity.
## Critical Microsoft Vulnerabilities Patched
CVE-2021-34448 – Scripting Engine Memory Corruption Vulnerability
This is being actively exploited. The vulnerability allows an attacker to execute malicious code on a compromised website if a user browses to a specially crafted file on the website. The vendor has assigned a CVSSv3 base score of 6.8 and should be prioritized for patching.
CVE-2021-34494 – Windows DNS Server Remote Code Execution Vulnerability
Microsoft released patches addressing a critical RCE vulnerability in Windows DNS Server (CVE-2021-34494). This CVE has a high likelihood of exploitability and is assign
Krebs
Microsoft Patch Tuesday, July 2021 Edition
blogs_krebs·2021-07-13·CVSS 7.8
[HIGH] Microsoft Patch Tuesday, July 2021 Edition
Microsoft today released updates to patch at least 116 security holes in its Windows operating systems and related software. At least four of the vulnerabilities addressed today are under active attack, according to Microsoft.
Thirteen of the security bugs quashed in this month’s release earned Microsoft’s most-dire “critical” rating, meaning they can be exploited by malware or miscreants to seize remote control over a vulnerable system without any help from users.
Another 103 of the security holes patched this month were flagged as “important,” which Microsoft assigns to vulnerabilities “whose exploitation could result in compromise of the confidentiality, integrity, or availability of user data, or of the integrity or availability of processing resources.”
Among the critical bugs is o
Trendmicro
July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
blogs_trendmicro·2021-07-13·CVSS 9.1
[CRITICAL] July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
Exploits & Vulnerabilities
## July Patch Tuesday: DNS Server, Exchange Server Vulnerabilities Cause Problems
After two relatively quiet months, July has proven to be another busy month for Microsoft security bulletins. A total of 117 bulletins were issued for various security vulnerabilities fixed in the July Patch Tuesday cycle.
By: Trend Micro Jul 13, 2021 Read time: ( words)
Save to Folio
After two relatively quiet months, July has proven to be another busy month for Microsoft security bulletins. A total of 117 bulletins were issued for various security vulnerabilities fixed in the July Patch Tuesday cycle. Thirteen of these were rated as Critical, 103 as Important, and one was classified as Moderate. Fifteen were submitted via the Trend Micro Zero Day Initiative .
PrintNightmare
Krebs
Microsoft Patch Tuesday, July 2021 Edition
blogs_krebs·2021-07-13·CVSS 7.8
[HIGH] Microsoft Patch Tuesday, July 2021 Edition
Microsoft today released updates to patch at least 116 security holes in its Windows operating systems and related software. At least four of the vulnerabilities addressed today are under active attack, according to Microsoft.
Thirteen of the security bugs quashed in this month’s release earned Microsoft’s most-dire “critical” rating, meaning they can be exploited by malware or miscreants to seize remote control over a vulnerable system without any help from users.
Another 103 of the security holes patched this month were flagged as “important,” which Microsoft assigns to vulnerabilities “whose exploitation could result in compromise of the confidentiality, integrity, or availability of user data, or of the integrity or availability of processing resources.”
Among the critical bugs is o
Tenable
PrintNightmare
blogs_tenable·2021-07-13·CVSS 7.8
CVE-2021-34527 [HIGH] PrintNightmare
by Josef Weiss July 13, 2021
On July 6, Microsoft updated its advisory to announce the availability of out-of-band patches for a critical vulnerability in its Windows Print Spooler that researchers are calling PrintNightmare. Microsoft originally released its advisory for CVE-2021-34527 on July 1. This advisory was released in response to public reports about a proof-of-concept (PoC) exploit for CVE-2021-1675, a similar vulnerability in the Windows Print Spooler. To help clear up confusion about the vulnerability, Microsoft updated its advisory for CVE-2021-1675 to clarify that it is “similar but distinct from CVE-2021-34527.” This remote code execution (RCE) vulnerability affects all versions of Microsoft Windows.
CVE-2021-34527 is an RCE vulnerability in the Windows Print Spooler Servi
Checkpoint
12th July – Threat Intelligence Report
blogs_checkpoint·2021-07-12
CVE-2021-34527 12th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 12th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 12th July, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The Kaseya supply-chain ransomware attack has hit 1,500 organizations and breached the systems of roughly 60 of Kaseya’s direct customers. After first demanding a $5 million ransom per MSP and $55K per customer for an individual decryptor, the Sodinokibi (REvil) threat group proposed to release a universal decryptor for $70 mil
Trendmicro
This Week in Security News - July 9, 2021
blogs_trendmicro·2021-07-09
This Week in Security News - July 9, 2021
Ciberdelincuencia
## This Week in Security News - July 9, 2021
Kaseya hit with ransomware attack and top 3 mobile threat takeaways from MWC
By: Jon Clay Jul 09, 2021 Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about cybersecurity news and events that happened over the past few days. This week, learn about the REvil ransomware attack on IT management platform Kaseya. Also, read the top security takeaways from this year’s Mobile World Congress conference.
Read on:
IT Management Platform Kaseya Hit with Sodinokibi REvil Ransomware Attack
Kaseya, a company that provides IT management software to managed service providers (MSPs) and IT companies, has been hit with a REvil (aka Sodinokibi) ransomware attack at the dawn of the Four
Trendmicro
This Week in Security News - July 9, 2021
blogs_trendmicro·2021-07-09
This Week in Security News - July 9, 2021
Cyber Crime
## This Week in Security News - July 9, 2021
Kaseya hit with ransomware attack and top 3 mobile threat takeaways from MWC
By: Jon Clay 2021/07/09 Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about cybersecurity news and events that happened over the past few days. This week, learn about the REvil ransomware attack on IT management platform Kaseya. Also, read the top security takeaways from this year’s Mobile World Congress conference.
Read on:
IT Management Platform Kaseya Hit with Sodinokibi REvil Ransomware Attack
Kaseya, a company that provides IT management software to managed service providers (MSPs) and IT companies, has been hit with a REvil (aka Sodinokibi) ransomware attack at the dawn of the Fourth of Ju
Trendmicro
This Week in Security News - July 9, 2021
blogs_trendmicro·2021-07-09
This Week in Security News - July 9, 2021
Cyber Crime
## This Week in Security News - July 9, 2021
Kaseya hit with ransomware attack and top 3 mobile threat takeaways from MWC
By: Jon Clay Jul 09, 2021 Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about cybersecurity news and events that happened over the past few days. This week, learn about the REvil ransomware attack on IT management platform Kaseya. Also, read the top security takeaways from this year’s Mobile World Congress conference.
Read on:
IT Management Platform Kaseya Hit with Sodinokibi REvil Ransomware Attack
Kaseya, a company that provides IT management software to managed service providers (MSPs) and IT companies, has been hit with a REvil (aka Sodinokibi) ransomware attack at the dawn of the Fourth of
Trendmicro
This Week in Security News - July 9, 2021
blogs_trendmicro·2021-07-09
This Week in Security News - July 9, 2021
Cyber Crime
# This Week in Security News - July 9, 2021
Kaseya hit with ransomware attack and top 3 mobile threat takeaways from MWC
By: Jon Clay
2021/07/09
Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about cybersecurity news and events that happened over the past few days. This week, learn about the REvil ransomware attack on IT management platform Kaseya. Also, read the top security takeaways from this year’s Mobile World Congress conference.
Read on:
IT Management Platform Kaseya Hit with Sodinokibi REvil Ransomware Attack
Kaseya, a company that provides IT management software to managed service providers (MSPs) and IT companies, has been hit with a REvil (aka Sodinokibi) ransomware attack at the dawn of the Fourth of Ju
Trendmicro
This Week in Security News - July 9, 2021
blogs_trendmicro·2021-07-09
This Week in Security News - July 9, 2021
Cyber-Kriminalität
## This Week in Security News - July 9, 2021
Kaseya hit with ransomware attack and top 3 mobile threat takeaways from MWC
By: Jon Clay Jul 09, 2021 Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about cybersecurity news and events that happened over the past few days. This week, learn about the REvil ransomware attack on IT management platform Kaseya. Also, read the top security takeaways from this year’s Mobile World Congress conference.
Read on:
IT Management Platform Kaseya Hit with Sodinokibi REvil Ransomware Attack
Kaseya, a company that provides IT management software to managed service providers (MSPs) and IT companies, has been hit with a REvil (aka Sodinokibi) ransomware attack at the dawn of the Fou
Talos
PrintNightmare: Here’s what you need to know and Talos’ coverage
blogs_talos·2021-07-08·CVSS 7.8
CVE-2021-1675 [HIGH] PrintNightmare: Here’s what you need to know and Talos’ coverage
Over the past several weeks, there's been a lot of discussion about a particular privilege escalation vulnerability in Windows affecting the print spooler, dubbed PrintNightmare. The vulnerability (CVE-2021-1675/CVE-2021-34527) has now been patched multiple times but is believed to still be exploitable.
The vulnerability itself is a privilege escalation bug found in the print spooler service on Windows platforms. It was believed to allow authenticated users to achieve escalated privileges, including admin rights. The vulnerability's severity was complicated by the fact that, if triggered, the vulnerability could affect domain controllers in enterprise networks. To make matters worse, this privilege escalation vulnerability can be used to achieve remote code execution. This can be done by
Krebs
Microsoft Issues Emergency Patch for Windows Flaw
blogs_krebs·2021-07-08·CVSS 8.8
CVE-2021-34527 [HIGH] Microsoft Issues Emergency Patch for Windows Flaw
Microsoft on Tuesday issued an emergency software update to quash a security bug that’s been dubbed “PrintNightmare,” a critical vulnerability in all supported versions of Windows that is actively being exploited. The fix comes a week ahead of Microsoft’s normal monthly Patch Tuesday release, and follows the publishing of exploit code showing would-be attackers how to leverage the flaw to break into Windows computers.
At issue is CVE-2021-34527, which involves a flaw in the Windows Print Spooler service that could be exploited by attackers to run code of their choice on a target’s system. Microsoft says it has already detected active exploitation of the vulnerability.
Satnam Narang, staff research engineer at Tenable, said Microsoft’s patch warrants urgent attention because of the vulner
Securelist
Quick look at CVE-2021-1675 & CVE-2021-34527 (aka PrintNightmare)
blogs_securelist·2021-07-08·CVSS 7.8
CVE-2021-1675 [HIGH] Quick look at CVE-2021-1675 & CVE-2021-34527 (aka PrintNightmare)
Table of Contents
- Summary
- Technical details
- Mitigations
Authors
- Kaspersky
## Recent vulnerabilities in Windows Print Spooler service
## Summary
Last week Microsoft warned Windows users about vulnerabilities in the Windows Print Spooler service – CVE-2021-1675 and CVE-2021-34527 (also known as PrintNightmare). Both vulnerabilities can be used by an attacker with a regular user account to take control of a vulnerable server or client machine that runs the Windows Print Spooler service. This service is enabled by default on all Windows clients and servers, including domain controllers.
Kaspersky products protect against attacks leveraging these vulnerabilities. The following detection names are used:
- HEUR:Exploit.Win32.CVE-2021-1675.*
- HEUR:Exploit.Win32.CVE-2021-34527.*
-
Securelist
Quick look at CVE-2021-1675 & CVE-2021-34527 (aka PrintNightmare)
blogs_securelist·2021-07-08·CVSS 7.8
CVE-2021-34527 [HIGH] Quick look at CVE-2021-1675 & CVE-2021-34527 (aka PrintNightmare)
Table of Contents
Summary
Technical details
CVE-2021-34527
CVE-2021-1675
Mitigations
Authors
Kaspersky
## Recent vulnerabilities in Windows Print Spooler service
## Summary
Last week Microsoft warned Windows users about vulnerabilities in the Windows Print Spooler service – CVE-2021-1675 and CVE-2021-34527 (also known as PrintNightmare). Both vulnerabilities can be used by an attacker with a regular user account to take control of a vulnerable server or client machine that runs the Windows Print Spooler service. This service is enabled by default on all Windows clients and servers, including domain controllers.
Kaspersky products protect against attacks leveraging these vulnerabilities. The following detection names are used:
HEUR:Exploit.Win32.CVE-2021-1675.*
HEUR:Exploit.Win
Talos
PrintNightmare: Here’s what you need to know and Talos’ coverage
blogs_talos·2021-07-08·CVSS 7.8
CVE-2021-1675 [HIGH] PrintNightmare: Here’s what you need to know and Talos’ coverage
## PrintNightmare: Here’s what you need to know and Talos’ coverage
Over the past several weeks, there's been a lot of discussion about a particular privilege escalation vulnerability in Windows affecting the print spooler, dubbed PrintNightmare. The vulnerability ( CVE-2021-1675 / CVE-2021-34527 ) has now been patched multiple times but is believed to still be exploitable .
The vulnerability itself is a privilege escalation bug found in the print spooler service on Windows platforms. It was believed to allow authenticated users to achieve escalated privileges, including admin rights. The vulnerability's severity was complicated by the fact that, if triggered, the vulnerability could affect domain controllers in enterprise networks. To make matters worse, this privilege escalation vulner
Qualys
Microsoft Windows Print Spooler RCE Vulnerability (PrintNightmare-CVE-2021-34527) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR®
blogs_qualys·2021-07-07·CVSS 8.8
CVE-2021-34527 [HIGH] Microsoft Windows Print Spooler RCE Vulnerability (PrintNightmare-CVE-2021-34527) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR®
## Table of Contents
About PrintNightmare
Affected Products
Identify Assets, Discover, Prioritize and Remediate Using Qualys VMDR
Identification of Windows Assets with Print Spooler Running
Discover PrintNightmare CVE-2021-34527 Vulnerability
Dashboard
Response by Patching and Remediation
Identify and Address System Misconfigurations
Registry Settings Check After Installing the Updates
Workaround
Get Started Now
Update July 9, 2021 : Added “Registry Settings Check After Installing the Updates” section below.
Original Post : On June 29, 2021, a zero-day exploit was observed on Microsoft Windows systems which allows authenticated users with a regular Domain User account to gain full SYSTEM-level privileges. On July 1, 2021, Microsoft released a separate advisory linking this zer
Tenable
CVE-2021-34527: Microsoft Releases Out-of-Band Patch for PrintNightmare Vulnerability in Windows Print Spooler
blogs_tenable·2021-07-07·CVSS 8.8
[HIGH] CVE-2021-34527: Microsoft Releases Out-of-Band Patch for PrintNightmare Vulnerability in Windows Print Spooler
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Krebs
Microsoft Issues Emergency Patch for Windows Flaw
blogs_krebs·2021-07-07·CVSS 8.8
CVE-2021-34527 [HIGH] Microsoft Issues Emergency Patch for Windows Flaw
Microsoft on Tuesday issued an emergency software update to quash a security bug that’s been dubbed “ PrintNightmare ,” a critical vulnerability in all supported versions of Windows that is actively being exploited. The fix comes a week ahead of Microsoft’s normal monthly Patch Tuesday release, and follows the publishing of exploit code showing would-be attackers how to leverage the flaw to break into Windows computers.
At issue is CVE-2021-34527 , which involves a flaw in the Windows Print Spooler service that could be exploited by attackers to run code of their choice on a target’s system. Microsoft says it has already detected active exploitation of the vulnerability.
Satnam Narang , staff research engineer at Tenable , said Microsoft’s patch warrants urgent attention because of the v
Qualys
Microsoft Windows Print Spooler RCE Vulnerability (PrintNightmare-CVE-2021-34527) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR® | Qualys
blogs_qualys·2021-07-07·CVSS 8.8
CVE-2021-34527 [HIGH] Microsoft Windows Print Spooler RCE Vulnerability (PrintNightmare-CVE-2021-34527) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR® | Qualys
#### Table of Contents
- About PrintNightmare
- Affected Products
- Identify Assets, Discover, Prioritize and Remediate Using Qualys VMDR
- Identification of Windows Assets with Print Spooler Running
- Discover PrintNightmare CVE-2021-34527 Vulnerability
- Dashboard
- Response by Patching and Remediation
- Identify and Address System Misconfigurations
- Registry Settings Check After Installing the Updates
- Workaround
- Get Started Now
Update July 9, 2021: Added “Registry Settings Check After Installing the Updates” section below.
Original Post: On June 29, 2021, a zero-day exploit was observed on Microsoft Windows systems which allows authenticated users with a regular Domain User account to gain full SYSTEM-level privileges. On July 1, 2021, Microsoft released a separate advisory link
Checkpoint
5th July – Threat Intelligence Report
blogs_checkpoint·2021-07-05
CVE-2021-34527 5th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 5th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 5th July, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research has discovered an ongoing cyber espionage operation targeting the Afghan government. Believed to be the Chinese-speaking hacker group known as “IndigoZebra”, the threat actors behind the espionage leveraged Dropbox to infiltrate the Afghan National Security Council (NSC). This is the latest in longer-running
Fortinet
Fortinet Releases IPS Signature for Microsoft PrintNightmare Vulnerability | FortiGuard Labs
blogs_fortinet·2021-07-01·CVSS 7.8
[HIGH] Fortinet Releases IPS Signature for Microsoft PrintNightmare Vulnerability | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Fortinet Releases IPS Signature for Microsoft PrintNightmare Vulnerability
By FortiGuard Labs | July 01, 2021
FortiGuard Labs Breaking Update
A potentially new zero-day Microsoft vulnerability, dubbed "PrintNightmare," makes it possible for any authenticated attacker to remotely execute code with SYSTEM privileges on any machine that has the Windows Print Spooler service enabled (which is the default setting). Security researchers initially believed this vulnerability to be tied to CVE-2021-1675 (Windows Print Spooler Remote Code Execution Vulnerability), which was first disclosed in the June 8, 2021, Microsoft Patch Tuesday release. But there is now some question about whether this is the same issue or a new zero-day vulnerability.
Last week, researcher
Huntress
Critical Vuln.: PrintNightmare Exposes Windows Servers to RCE | Huntress
blogs_huntress·2021-06-30·CVSS 7.8
CVE-2021-1675 [HIGH] Critical Vuln.: PrintNightmare Exposes Windows Servers to RCE | Huntress
On June 29, Huntress was made aware of CVE-2021-1675 (now termed CVE-2021-34527) , a critical remote code execution and local privilege escalation vulnerability dubbed “PrintNightmare.”
Microsoft released a patch on June 8 considering this vulnerability low in severity. On June 21, PrintNightmare was updated to critical severity as the potential for remote code execution was uncovered. The June 8 Microsoft patch did not successfully resolve the issue for CVE-2021-32547 PrintNightmare, but it did resolve CVE-2021-1675.
UPDATE July 07 @ 12pm ET: On July 6, Microsoft updated their advisory on CVE-2021-34527 and released emergency patches, but the effectiveness of this security update is still under scrutiny.
Members of our Huntress team have validated the new patch on Windows 21H1 Enterpri
Tenable
CVE-2021-1675: Proof-of-Concept Leaked for Critical Windows Print Spooler Vulnerability
blogs_tenable·2021-06-29·CVSS 7.8
[HIGH] CVE-2021-1675: Proof-of-Concept Leaked for Critical Windows Print Spooler Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
Ransomware by the numbers: Reassessing the threat’s global impact
blogs_securelist·2021-04-23
Ransomware by the numbers: Reassessing the threat’s global impact
Table of Contents
- Key findings
- Methodology
- Ransomware across all platforms
- Mobile ransomware
- The rise of targeted ransomware
- Conclusion
Authors
- Kaspersky
Kaspersky has been following the ransomware landscape for years. In the past, we’ve published yearly reports on the subject: PC ransomware in 2014-2016, Ransomware in 2016-2017, and Ransomware and malicious crypto miners in 2016-2018. In fact, in 2019, we chose ransomware as the story of the year, upon noticing the well-known threat was shifting its attention to municipalities. In the 2010s, with campaigns like WannaCry and NotPetya, ransomware became mainstream news. However, starting in 2018, we began noticing something else: the statistics for the overall number of ransomware detections were on a steep decline. What
Securelist
How we protect our users against the Sunburst backdoor
blogs_securelist·2020-12-23
How we protect our users against the Sunburst backdoor
Authors
- Kaspersky
## What happened
SolarWinds, a well-known IT managed services provider, has recently become a victim of a cyberattack. Their product Orion Platform, a solution for monitoring and managing their customers’ IT infrastructure, was compromised by threat actors. This resulted in the deployment of a custom Sunburst backdoor on the networks of more than 18,000 SolarWinds customers, with many large corporations and government entities among the victims.
According to our Threat Intelligence data, the victims of this sophisticated supply-chain attack were located all around the globe: the Americas, Europe, Middle East, Africa and Asia.
After the initial compromise, the attackers appear to have chosen the most valuable targets among their victims. The companies that appeared
Zscaler
Zscaler found Windows vulnerabilities | 07-13-2021
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler found Windows vulnerabilities | 07-13-2021
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Recorded Future
Patterns and Targets for Ransomware Exploitation of Vulnerabilities: 2017–2023
blogs_recorded_future
Patterns and Targets for Ransomware Exploitation of Vulnerabilities: 2017–2023
# Patterns and Targets for Ransomware Exploitation of Vulnerabilities: 2017–2023
Recent Insikt research analyzes ransomware and vulnerability trends spanning the past six years and offers insights into future expectations.
Ransomware groups exploit vulnerabilities in two distinct categories: those targeted by only a few groups and those widely exploited by several. Each category necessitates different defense strategies. Groups targeting specific vulnerabilities tend to follow particular patterns, enabling companies to prioritize defenses and audits. To defend against unique exploitation, understanding the likely targets and vulnerability types is crucial.
Diagram showing the number of ransomware groups that have been associated with vulnerability exploitation in the last five years. By
Crowdstrike
How CrowdStrike Protects Against PrintNightmare Vulnerability
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] How CrowdStrike Protects Against PrintNightmare Vulnerability
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Recorded Future
Patterns and Targets for Ransomware Exploitation of Vulnerabilities: 2017–2023
blogs_recorded_future
Patterns and Targets for Ransomware Exploitation of Vulnerabilities: 2017–2023
## Patterns and Targets for Ransomware Exploitation of Vulnerabilities: 2017–2023
Recent Insikt research analyzes ransomware and vulnerability trends spanning the past six years and offers insights into future expectations.
Ransomware groups exploit vulnerabilities in two distinct categories: those targeted by only a few groups and those widely exploited by several. Each category necessitates different defense strategies. Groups targeting specific vulnerabilities tend to follow particular patterns, enabling companies to prioritize defenses and audits. To defend against unique exploitation, understanding the likely targets and vulnerability types is crucial.
Widely exploited vulnerabilities are found in commonly used enterprise software and are easily exploited through various means like
Crowdstrike
Patch Tuesday 2021: A Vulnerability Deep Dive
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Patch Tuesday 2021: A Vulnerability Deep Dive
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Crowdstrike
Magniber Ransomware Caught Using PrintNightmare Vulnerability
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Magniber Ransomware Caught Using PrintNightmare Vulnerability
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
July 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] July 2021 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Sentinelone
Vice Society
blogs_sentinelone·CVSS 7.8
[HIGH] Vice Society
# Vice Society Ransomware: In-Depth Analysis, Detection, and Mitigation
## What is Vice Society Ransomware?
Vice Society is a multi-pronged extortion and ransomware group which emerged in early to mid 2021. The group also leverages both Windows and Linux variations of ransomware. The latter of which is frequently observed in campaigns targeting ESXi or heavily virtualized environments. Vice Society is known to ‘outsource’ the development of their ransomware payloads.
## What Does Vice Society Ransomware Target?
Vice Society ransomware is known to target large enterprises and high-value targets as well as medium-sized businesses. They have also been known to focus on organizations in the government, healthcare, and educational sectors. Vice Society is observed to heavily target virtuali
Huntress
Critical Vuln.: PrintNightmare Exposes Windows Servers to RCE | Huntress
blogs_huntress·CVSS 7.8
CVE-2021-1675 [HIGH] Critical Vuln.: PrintNightmare Exposes Windows Servers to RCE | Huntress
On June 29, Huntress was made aware of CVE-2021-1675 (now termed CVE-2021-34527), a critical remote code execution and local privilege escalation vulnerability dubbed “PrintNightmare.”
Microsoft released a patch on June 8 considering this vulnerability low in severity. On June 21, PrintNightmare was updated to critical severity as the potential for remote code execution was uncovered. The June 8 Microsoft patch did not successfully resolve the issue for CVE-2021-32547 PrintNightmare, but it did resolve CVE-2021-1675.
UPDATE July 07 @ 12pm ET: On July 6, Microsoft updated their advisory on CVE-2021-34527 and released emergency patches, but the effectiveness of this security update is still under scrutiny.
Members of our Huntress team have validated the new patch on Windows 21H1 Enterpris
Crowdstrike
July 2021 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] July 2021 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
Patch Tuesday 2021: A Vulnerability Deep Dive
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Patch Tuesday 2021: A Vulnerability Deep Dive
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Sentinelone
Black Basta
blogs_sentinelone
Black Basta
# Black Basta Ransomware: In-Depth Analysis, Detection, and Mitigation
## Summary of Black Basta Ransomware
Black Basta first emerged in early 2022. The ransomware family is an evolution of the Hermes/Ryuk/Conti families. Black Basta was heavily advertised in underground cybercrime markets. Black Basta practices double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data. There are Windows and LInux variants of Black Basta ransomware. The group is responsible for hundreds of attacks against global targets of varying sectors.
February 2025 Update: Nearly a year’s worth of Black Basta chat logs have been released on Telegram, providing detailed insight into the groups operational workflow, reconnaissance activities, and specific userID and details o
Crowdstrike
Magniber Ransomware Caught Using PrintNightmare Vulnerability
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Magniber Ransomware Caught Using PrintNightmare Vulnerability
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
arXiv
POLAR: Automating Cyber Threat Prioritization through LLM-Powered Assessment
arxiv_fulltext·2025-10-02
POLAR: Automating Cyber Threat Prioritization through LLM-Powered Assessment
## Abstract
The rapid expansion of the cyber threat landscape, with over 11,000 new vulnerabilities reported in 2024 alone, has intensified the need for effective threat prioritization. Existing approaches, from rule-based systems to machine learning models, struggle with scalability, distribution shift, and context-independent scoring, often mis-ranking threats in dynamic exploitation environments. In this work, we present , an LLM-based framework that automates cyber threat prioritization across four sequential stages: Triage, Static Analysis, Exploitation Analysis, and Mitigation Recommendation. leverages LLM reasoning to transform unstructured threat intelligence into structured severity metrics, forecast exploitation likelihood using temporal narratives, and generate prioritized miti
arXiv
Do Chase Your Tail! Missing Key Aspects Augmentation in Textual Vulnerability Descriptions of Long-tail Software through Feature Inference
arxiv_fulltext·2024-12-15
Do Chase Your Tail! Missing Key Aspects Augmentation in Textual Vulnerability Descriptions of Long-tail Software through Feature Inference
Do Chase Your Tail! Missing Key Aspects Augmentation in Textual Vulnerability Descriptions of Long-tail Software through Feature Inference
Linyi Han, Shidong Pan, Zhenchang Xing, Jiamou Sun, Sofonias Yitagesu, Xiaowang Zhang, Zhiyong Feng
Manuscript received XXX XXX, 20XX. (Corresponding author: Xiaowang Zhang)
Linyi Han, Sofonias Yitagesu, Xiaowang Zhang, and Zhiyong Feng are with the College of Intelligence and Computing, Tianjin University, Tianjin, China. e-mail: \hanly2, xiaowangzhang, zyfeng\@tju.edu.cn and [email protected].
Shidong Pan, Zhenchang Xing, and Jiamou Sun are with the CSIRO's Data61, Canberra, Australia. e-mail: \Shidong.Pan, Zhenchang.Xing, Frank.Sun\@data61.csiro.au
Linyi Han is also the Center of National Railway Intelligent Transportation System Engineeri
CTF
CVE-XXXX-XXXX / README
ctf_writeups·2022·CVSS 8.8
CVE-2021-34527 [HIGH] CVE-XXXX-XXXX / README
- This is the PrintNightmare vuln, which is called [CVE-2021-34527](https://www.cisa.gov/uscert/ncas/current-activity/2021/06/30/printnightmare-critical-windows-print-spooler-vulnerability)
picoCTF{CVE-2021-34527}
CTF
Binary_Exploitation / CVE-XXXX-XXXX
ctf_writeups·2022·CVSS 8.8
[HIGH] Binary_Exploitation / CVE-XXXX-XXXX
# CVE-XXXX-XXXX
- [Challenge information](#challenge-information)
- [Solution](#solution)
## Challenge information
```text
Level: Medium
Tags: picoCTF 2022, Binary Exploitation
Meta Tags: Walkthrough, Walk-through, Write-up, Writeup
Author: MUBARAK MIKAIL
Description:
The CVE we're looking for is the first recorded remote code execution (RCE) vulnerability in 2021 in
the Windows Print Spooler Service, which is available across desktop and server versions of Windows
operating systems. The service is used to manage printers and print servers.
Enter the CVE of the vulnerability as the flag with the correct flag format:
picoCTF{CVE-XXXX-XXXXX} replacing XXXX-XXXXX with the numbers for the matching vulnerability.
Hints:
1. We're not looking for the Local Spooler vulnerability in 2021...
CTF
PicoCTF 2022 / PicoCTF 2022 - Binary Exploitation Writeup
ctf_writeups·2022
PicoCTF 2022 / PicoCTF 2022 - Binary Exploitation Writeup
# Binary Exploitation
## basic-file-exploit
Vulnerable part of the code in function `data_read()`:
```c
if ((entry_number = strtol(entry, NULL, 10)) == 0) {
puts(flag);
fseek(stdin, 0, SEEK_END);
exit(0);
}
```
To enter this if-statement to get the flag, `entry`, which is our input, needs to start with "0".
Before entering this statement, we need to set `inputs`, which is done in `data_write()` function.
As such, the flow is:
1. Run data_write() with proper input values.
2. Run data_read() with `entry` as 0.
```sh
>> nc saturn.picoctf.net 53641
Hi, welcome to my echo chamber!
Type '1' to enter a phrase into our database
Type '2' to echo a phrase in our database
Type '3' to exit the program
>> 1
1
Please enter your data:
>> 1
1
Please enter the length of your data:
>> 1
1
Your entry
CTF
100-CVE-XXXX-XXXX / README
ctf_writeups·2022·CVSS 8.8
CVE-2021-34527 [HIGH] 100-CVE-XXXX-XXXX / README
# CVE-XXXX-XXXX - picoCTF 2022 - CMU Cybersecurity Competition
Binary Exploitation, 100 Points
## Description
## CVE-XXXX-XXXX Solution
We need to find the CVE number of ```Print Spooler```.
The CVE number is [CVE-2021-34527](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527) so the flag is ```picoCTF{CVE-2021-34527}```
CTF
08. Introduction to Active Directory / Introduction to Active Directory
ctf_writeups
08. Introduction to Active Directory / Introduction to Active Directory
# Introduction to Active Directory
Tags: #🧑🎓
Related to: [[w_add-adgroupmember]], [[w_add-computer]], [[w_copy-gpo]], [[w_get-adcomputer]], [[w_get-command]], [[w_get-help]], [[w_get-module]], [[w_import-module]], [[w_new-adgroup]], [[w_new-adorganizationalunit]], [[w_new-aduser]], [[w_remove-aduser]], [[w_set-adaccountpassword]], [[w_set-aduser]], [[w_set-gplink]], [[w_unlock-adaccount]], [[xfreerdp]]
See also:
Previous: [[HTB Academy]]
![[logo_introduction_to_active_directory.png]]
Active Directory (AD) is present in the majority of corporate environments. Due to its many features and complexity, it presents a vast attack surface. To be successful as penetration testers and information security professionals, we must have a firm understanding of Active Directory fundamentals, AD stru
CTF
Driver / README
ctf_writeups
Driver / README
# Driver Writeup
## Enumeration
### Nmap
First, let's scan for open ports using `nmap`. We can quickly scan for open ports and store them in a variable: `ports=$(nmap -p- --min-rate=1000 -T4 10.10.11.106 | grep ^[0-9] | cut -d '/' -f 1 | tr '\n' ',' | sed s/,$//)`. Then, we can scan those specific ports in depth by running `nmap`'s built-in scripts: `nmap -p$ports -sC -sV 10.10.11.106`.
```
PORT STATE SERVICE VERSION
80/tcp open http Microsoft IIS httpd 10.0
| http-methods:
|_ Potentially risky methods: TRACE
|_http-title: Site doesn't have a title (text/html; charset=UTF-8).
| http-auth:
| HTTP/1.1 401 Unauthorized\x0D
|_ Basic realm=MFP Firmware Update Center. Please enter password for admin
|_http-server-header: Microsoft-IIS/10.0
135/tcp open msrpc Microsoft Windows RPC
445/tcp ope
http://packetstormsecurity.com/files/167261/Print-Spooler-Remote-DLL-Injection.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34527http://packetstormsecurity.com/files/167261/Print-Spooler-Remote-DLL-Injection.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34527https://www.kb.cert.org/vuls/id/383432https://www.vicarius.io/vsociety/posts/cve-2021-34527-printnightmare-detection-scripthttps://www.vicarius.io/vsociety/posts/cve-2021-34527-printnightmare-mitigation-scripthttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-34527
2021-07-02
Published
2021-11-03
Added to CISA KEV
Exploited in the wild