Open in app

Sign In

Write

Sign In

Kevin Beaumont
Kevin Beaumont

3.7K Followers

Home

About

Published in DoublePulsar

·Mar 15

A look at CVE-2023–23415 — a Windows ICMP vulnerability + mitigations (which is not a cyber meltdown)

Yesterday Microsoft dropped a patch for a vulnerability found by @[email protected] It’s a great vuln, in theory allowing code execution over ICMP. It also sounds really scary, as it’s a high CVSS score in Windows OS on a commonly used protocol. I’ve had a quick reverse engineer of the patch…

Cybersecurity News

3 min read

A look at CVE-2023–23415 — a Windows ICMP vulnerability + mitigations which is not a cyber meltdown
A look at CVE-2023–23415 — a Windows ICMP vulnerability + mitigations which is not a cyber meltdown
Cybersecurity News

3 min read


Published in DoublePulsar

·Feb 9

UK government declares ransomware a “tier 1” national security threat — on par with terrorism and military crisis between states.

Those who have known me for a long time will know I’ve been banging on about ransomware for years. On here, on Twitter, in person. Here, I documented things like the emergence of Locky 7 years ago, one of the first big single endpoint ransomware incidents. I worked with the…

Ransomware

4 min read

UK government declares ransomware a “tier 1” national security threat — on par with terrorism and…
UK government declares ransomware a “tier 1” national security threat — on par with terrorism and…
Ransomware

4 min read


Published in DoublePulsar

·Dec 8, 2022

Microsoft’s Github facilitating Ukraine government in denial of service of Russian government infrastructure

Back in February 2022, Mykhailo Fedorov — Ukraine’s Deputy Prime Minister — launched the IT Army of Ukraine: The army, which has grown to 300,000 people at peak, has been fighting a digital war with the Russian government and private enterprise. It has been incredibly successful — I have…

Cybersecurity

4 min read

Microsoft’s Github facilitating Ukraine government in denial of service of Russian government…
Microsoft’s Github facilitating Ukraine government in denial of service of Russian government…
Cybersecurity

4 min read


Published in DoublePulsar

·Dec 3, 2022

Rackspace Cloud Office suffers destructive security breach

Thousands of small to medium size businesses are suffering as Rackspace have suffered a security breach on their Hosted Exchange service. Rackspace have now confirmed this is a ransomware incident. Yesterday, 2nd December 2022, Rackspace announced an outage to their Hosted Exchange Server: Updated followed through the day, but were…

Cybersecurity

9 min read

Rackspace Cloud Office suffers destructive security breach
Rackspace Cloud Office suffers destructive security breach
Cybersecurity

9 min read


Published in DoublePulsar

·Sep 29, 2022

ProxyNotShell— the story of the claimed zero days in Microsoft Exchange

Yesterday, cybersecurity vendor GTSC Cyber Security dropped a blog saying they had detected exploitation of a new Microsoft Exchange zero day: Warning: New attack campaign utilized a new 0-day RCE vulnerability on Microsoft Exchange Server | Blog | GTSC — Cung cấp các dịch vụ bảo mật toàn diện (gteltsc.vn) …

Cybersecurity

10 min read

ProxyNotShell— the story of the claimed zero day in Microsoft Exchange
ProxyNotShell— the story of the claimed zero day in Microsoft Exchange
Cybersecurity

10 min read


Published in DoublePulsar

·May 29, 2022

Follina — a Microsoft Office code execution vulnerability

Two days ago, on May 27th 2022, Nao_sec identified an odd looking Word document in the wild, uploaded from an IP address in Belarus. This turned out to be a zero day vulnerability in Office and/or Windows. This caught my attention, as Defender for Endpoint missed execution: The…

Follina

9 min read

Follina — a Microsoft Office code execution vulnerability
Follina — a Microsoft Office code execution vulnerability
Follina

9 min read


Published in DoublePulsar

·May 7, 2022

BPFDoor — an active Chinese global surveillance tool

Recently, PwC Threat Intelligence documented the existence of BPFDoor, a passive network implant for Linux they attribute to Red Menshen, a Chinese threat actor group. You can read more in PwC’s great, yearly threat intelligence brief, here. PwC plan to present their findings in June: BPFDoor is interesting. It…

Bpfdoor

3 min read

BPFDoor — an active Chinese global surveillance tool
BPFDoor — an active Chinese global surveillance tool
Bpfdoor

3 min read


Published in DoublePulsar

·Aug 21, 2021

Multiple threat actors, including a ransomware gang, exploiting Exchange ProxyShell vulnerabilities

For nearly a month, I have been watching mass in the wild exploitation of ProxyShell, a set of vulnerabilities revealed by Orange Tsai at BlackHat. These vulnerabilities are worse than ProxyLogon, the Exchange vulnerabilities revealed in March — they are more exploitable, and organisations largely haven’t patched. This post goes…

Proxyshell

7 min read

Multiple threat actors, including a ransomware gang, exploiting Exchange ProxyShell vulnerabilities
Multiple threat actors, including a ransomware gang, exploiting Exchange ProxyShell vulnerabilities
Proxyshell

7 min read


Published in DoublePulsar

·Jul 20, 2021

#HiveNightmare aka #SeriousSAM — anybody can read the registry in Windows 10

This is the story of how all non-admin users can read the registry — and so elevate privileges and access sensitive credential information — on various flavours of Windows 10. It appears this vulnerability has existed for years, and nobody noticed. …

Cybersecurity

4 min read

#HiveNightmare aka #SeriousSAM — anybody can read the registry in Windows 10
#HiveNightmare aka #SeriousSAM — anybody can read the registry in Windows 10
Cybersecurity

4 min read


Published in DoublePulsar

·Jul 2, 2021

Kaseya supply chain attack delivers mass ransomware event to US companies

Kaseya VSA is a commonly used solution by MSPs — Managed Service Providers — in the United States and United Kingdom, which helps them manage their client systems. Kaseya’s website claims they have over 40,000 customers. Four hours ago, an apparent auto update in the product has delivered REvil ransomware. …

Cyberattack

8 min read

Kaseya supply chain attack delivers mass ransomware event to US companies
Kaseya supply chain attack delivers mass ransomware event to US companies
Cyberattack

8 min read

Kevin Beaumont

Kevin Beaumont

3.7K Followers

Everything here is my personal work and opinions.

Following
  • Mitch Edwards

    Mitch Edwards

  • Omar Santos

    Omar Santos

  • Mark Manson

    Mark Manson

  • Wil Wheaton

    Wil Wheaton

  • Jang

    Jang

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech