Matt Muir

82 posts

Matt Muir banner
Matt Muir

Matt Muir

@_mattmuir

Cloud Security Researcher

Katılım Mart 2018
358 Takip Edilen236 Takipçiler
Matt Muir
Matt Muir@_mattmuir·
Latest research from the lab. This is an interesting one! 4 new discovery/initial access tools were found. Each tool contained code to exploit common misconfigurations (and n-day vulnerability) in either YARN, Docker, Confluence or Redis
Cado@CadoSecurity

Cado Security Labs discover Spinning YARN, an emerging malware campaign using novel Golang payloads to exploit #Docker, Hadoop #YARN, #Confluence and #Redis hosts. Full analysis here: hubs.li/Q02nlVt-0 #cloudsecurity #cloudforensics #cloudIR #threatintel #spinningYARN

English
2
2
4
661
Matt Muir
Matt Muir@_mattmuir·
Our latest blog covering #Migo - a Golang miner targeting Redis. This one attempts to weaken the Redis server by issuing various config commands, before deploying a user mode rootkit to hide the miner cadosecurity.com/migo-a-redis-m…
English
1
1
2
621
Matt Muir
Matt Muir@_mattmuir·
🐈 Here’s a new blog from us covering a novel attack named “Commando Cat” 🐈 The fun never stops with these Docker-focused campaigns! cadosecurity.com/the-nine-lives…
English
1
2
5
357
Matt Muir
Matt Muir@_mattmuir·
Legion-specific activity includes the creation of a malicious IAM user with the name ms.boharas in AWS environments
English
0
0
0
69
Matt Muir
Matt Muir@_mattmuir·
CISA have today released an advisory on Androxgh0st, this cloud-focused malware is closely related to Legion and Fbot
English
1
2
4
514