Research

Join us on our cybersecurity research blog as we delve into the latest advancements and challenges in the field. Our content ranges from in-depth analyses of new vulnerabilities and threats to reviews of pioneering security technologies and methodologies. Designed for cybersecurity experts and enthusiasts alike, our blog offers detailed case studies, strategic insights, and forecasts that help readers navigate the complexities of protecting digital assets in an interconnected world.

Exploiting the Ultimate Essay Grader: A Prompt Injection Deep Dive
Offensive Security

Exploiting the Ultimate Essay Grader: A Prompt Injection Deep Dive

A hands-on look at a direct prompt injection vulnerability in an AI essay grader — how a hidden instruction block forced a perfect score, mapped against Pangea's prompt injection taxonomy.

·L0WK3Y
OSINT: Tracking a Session-Hijacking Cyberattack to an Australian Carpet Company
Intelligence

OSINT: Tracking a Session-Hijacking Cyberattack to an Australian Carpet Company

This article covers a post-incident OSINT investigation that linked a recent business email compromise back to an Australian carpet company, due to a DNS registration mishap by the attacker. Persistence and pivoting are key for investigators!

·SirPicklJohn
New Insights on the Ghost Ransomware Gang and their Peculiar Success
Research

New Insights on the Ghost Ransomware Gang and their Peculiar Success

This cyber threat intelligence investigation hunts ghosts - seeking to answer why the Ghost/Cring ransomware gang is so successful at eluding security researchers and being profitable, especially when they avoid phishing in favor of targeting known-vulnerabilities in internet-facing systems.

·SirPicklJohn
A Demonstration of the Potential for Modern LLM Abuse by Threat Actors
Research

A Demonstration of the Potential for Modern LLM Abuse by Threat Actors

This article details the findings of two studies that highlight how security vulnerabilities in publicly-accessible LLMs can present a threat to public security through the proliferation of malicious knowledge, guidance in committing illegal activities, and generation of malicious content.

·SirPicklJohn
2024 Recap of Cybersecurity, with Insights for the Future
Research

2024 Recap of Cybersecurity, with Insights for the Future

2024 saw record-breaking breaches, an incredible AI boom, novel techniques and attack chains, and highly sophisticated cybercrime & cyberwarfare operations. Cybersecurity came into the public purview due to the cascading effects of cyber incidents that affected millions of people worldwide.

·SirPicklJohn
Deeper Insights into the Recent U.S. Telecom Provider Hacks, and Chinese APT Activity
Research

Deeper Insights into the Recent U.S. Telecom Provider Hacks, and Chinese APT Activity

This cyber threat intelligence investigation covers the who, what, why, when, and how of the recent state-sponsored Chinese cyberattacks on U.S. telecommunications providers, as well as how they fit into a broader picture of cyber-espionage that displays years of rising geopolitical tensions.

·SirPicklJohn
Discord Users Beware: Lumma Stealer Malware Lurking in Your Communities
Research

Discord Users Beware: Lumma Stealer Malware Lurking in Your Communities

Cosmo Whales is an infostealer campaign masquerading as a Web3 videogame. Threat actors have been observed in the wild distributing malware via job advertisements for a Web3 game called Cosmo Whales.

·L0WK3Y
Malware Report: CrowdStrike's BSOD Bug and the Rise of Fake Support Scams
Research

Malware Report: CrowdStrike's BSOD Bug and the Rise of Fake Support Scams

In a dramatic turn of events, CrowdStrike's latest update inadvertently triggered the dreaded Blue Screen of Death (BSOD) for numerous users. As if the chaos wasn't enough, opportunistic threat actors seized the moment, posing as CrowdStrike support to distribute malware...

·L0WK3Y
Malware Report: Wannacry Ransomware
Malware Analysis/RE

Malware Report: Wannacry Ransomware

Wannacry is a ransomware that utilized the EternalBlue exploit to propagate through the targets network and attacked outdated Windows computers globally in May of 2017.

·L0WK3Y