Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

research

20 articles

Elastic Security Labs research Oct 8

What the 2025 Elastic Global Threat Report reveals about the evolving threat landscape

The 2025 Elastic Global Threat Report provides current insights on adversary trends and defender strategies derived from real-world telemetry.

Elastic Security Labs → Details

Elastic Security Labs research Oct 1

WARMCOOKIE One Year Later: New Features and Fresh Insights

A year later: Elastic Security Labs re-examines the WARMCOOKIE backdoor.

Elastic Security Labs → Details

Elastic Security Labs research Linux Sep 30

FlipSwitch: a Novel Syscall Hooking Technique

FlipSwitch offers a fresh look at bypassing Linux kernel defenses, revealing a new technique in the ongoing battle between cyber attackers and defenders.

Elastic Security Labs → Details

Elastic Security Labs research Sep 22

Elastic excels in AV-Comparatives EPR Test 2025: A closer look

Elastic shares results of the 2025 AV Comparatives EPR test

Elastic Security Labs → Details

Elastic Security Labs research Sep 19

MCP Tools: Attack Vectors and Defense Recommendations for Autonomous Agents

This research examines how Model Context Protocol (MCP) tools expand the attack surface for autonomous agents, detailing exploit vectors such as tool poisoni...

Elastic Security Labs → Details

PortSwigger Research research Sep 17

WebSocket Turbo Intruder: Unearthing the WebSocket Goldmine

Many testers and tools give up the moment a protocol upgrade to WebSocket occurs, or only perform shallow analysis.

PortSwigger Research → Details

Elastic Security Labs research Microsoft Linux Sep 4

Investigating a Mysteriously Malformed Authenticode Signature

An in-depth investigation tracing a Windows Authenticode validation failure from vague error codes to undocumented kernel routines.

Elastic Security Labs → Details

PortSwigger Research research Sep 3

Cookie Chaos: How to bypass __Host and __Secure cookie prefixes

Browsers added cookie prefixes to protect your sessions and stop attackers from setting harmful cookies.

PortSwigger Research → Details

PortSwigger Research research Aug 26

Inline Style Exfiltration: leaking data with chained CSS conditionals

I discovered how to use CSS to steal attribute data without selectors and stylesheet imports! This means you can now exploit CSS injection via style attributes!

T1041

PortSwigger Research → Details

PortSwigger Research research Aug 19

Beware the false false-positive: how to distinguish HTTP pipelining from request smuggling

Sometimes people think they've found HTTP request smuggling, when they're actually just observing HTTP keep-alive or pipelining.

PortSwigger Research → Details

Elastic Security Labs research Aug 12

Agentic Frameworks Summary

Agentic systems require security teams to balance autonomy with alignment, ensuring that AI agents can act independently while remaining goal-consistent and ...

Elastic Security Labs → Details

PortSwigger Research research Aug 6

HTTP/1.1 must die: the desync endgame

Abstract Upstream HTTP/1.1 is inherently insecure and regularly exposes millions of websites to hostile takeover.

PortSwigger Research → Details

Elastic Security Labs research Jul 29

MaaS Appeal: An Infostealer Rises From The Ashes

NOVABLIGHT is a NodeJS infostealer developed and sold as a MaaS offering; it is used primarily to steal credentials and compromise cryptowallets.

Elastic Security Labs → Details

PortSwigger Research research Jul 15

Repeater Strike: manual testing, amplified

Manual testing doesn't have to be repetitive.

PortSwigger Research → Details

Elastic Security Labs research Jul 3

Taking SHELLTER: a commercial evasion framework abused in-the-wild

Elastic Security Labs detected the recent emergence of infostealers using an illicitly acquired version of the commercial evasion framework, SHELLTER, to dep...

Elastic Security Labs → Details

Elastic Security Labs research Jul 2

How AI and contextual search enhance defence cybersecurity

Contextual search brings clarity, speed, and insight to defence security teams

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Jun 25

Microsoft Entra ID OAuth Phishing and Detections

This article explores OAuth phishing and token-based abuse in Microsoft Entra ID. Through emulation and analysis of tokens, scope, and device behavior during...

T1566

Elastic Security Labs → Details

Elastic Security Labs research Jun 18

A Wretch Client: From ClickFix deception to information stealer deployment

Elastic Security Labs detected a surge in ClickFix campaigns, using GHOSTPULSE to deploy Remote Access Trojans and data-stealing malware.

Elastic Security Labs → Details

Elastic Security Labs research Microsoft Jun 12

Call Stacks: No More Free Passes For Malware

We explore the immense value that call stacks bring to malware detection and why Elastic considers them to be vital Windows endpoint telemetry despite the ar...

Elastic Security Labs → Details

Elastic Security Labs research Jun 9

Elastic Security scores 100% in AV-Comparatives Business Security Test

Elastic Security nailed it with a perfect score of 100% in the most recent AV-Comparatives Business Security Test.

Elastic Security Labs → Details

«Previous page 1 ... 25 26 27 28 29 ... 38 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA