In this blog CERT.at's employees can post research and thoughts. This is done with least possible oversight, so opinions in blogposts are not necessary opinions of CERT.at
Alternatively you can receive CERT.at's blog as a feed.
IntelMQ Manager release 2.1.1 fixes critical security issue
The IntelMQ Manager version 2.1.1 released yesterday fixes a Remote Code Execution flaw (CWE-78: 'OS Command Injection'). The documentation for version 2.1.1 and installation instructions can be found on our GitHub repository.
IntelMQ Version 2.1.2 released
On 28th January, we released the IntelMQ maintenance version 2.1.2 containing only bugfixes for the 2.1.x release series. The documentation for version 2.1.2 and installation instructions can be found on our github repository.
The upcoming version 2.2.0 - and current development version - will have several new features to offer.
TRANSITS II in Utrecht
Dimitri Robl from CERT.at attended the TRANSITS II Training in Utrecht from 21. - 23. of January 2020. It was a lot of fun :)
Sextortion Spam Scientifically Scrutinized
Sextortion scams are one of the big newcomers in Internet fraud of the last year. In these campaigns spammers send e-mails which claim that they have hacked into the victim's computer and used its webcam to film the victim masturbating while surfing adult websites.
Topinambour & Windows event logs
* Block outgoing SMB traffic if you can.
* Hunt or Monitor for event ID 106 in "Microsoft-Windows-TaskScheduler%4Operational.evtx". ...
MeliCERTes Training in Vienna
New PGP-Keys
IntelMQ 1.1.1 released
CEF-2018-3 project submitted
CERT.at submitted a proposal under objective 1 for the CEF-TC-2018-3 call. We hope we will get funding, since this will allow us to improve the MeliCERTes platform and also work on a set of nice new cool features for IntelMQ, which is maintained at CERT.at and widely used throughout the community.