We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert Mikhail Lozhnikov discovered a flaw that could cause a sudden system sh…
[ ARCHIVE ]
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert Mikhail Lozhnikov discovered a flaw that could cause a sudden system sh…
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a situation often arises in which the fi…
At the end of June, the PT ESC team, during incident investigations, discovered a new group targeting at least oil and gas companies and the financial sector. D…
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail servers using the vulnerability CVE-2026-73570 and the TargetZimbra en…
He's not gsocket to you 😑 During the investigation of one of the incidents, PT ESC IR specialists came across a rather curious tool called hsocket (not to be co…
Recently, the Department for Comprehensive Response to Cyberthreats (PT ESC IR) received a number of samples of an Android banking trojan with remote control ca…
We will croc you 👻 PhantomCore continues to actively exploit misconfigurations in 1C to attack Russian organizations. We previously wrote about attacks on 1C us…
PT ESC specialists have recorded signs of attackers carrying out an attack through the standard functionality of the ViPNet MFTP service. As of the publication…
In 2026, a tool called VMkatz was published. In terms of functionality, it resembles the widely known Mimikatz tool, but unlike it, VMkatz's goal is to extract…
Looking inside ESE 🫣 During incident investigations, we at PT ESC IR regularly encounter the need to analyze databases in the ESE (Extensible Storage Engine) fo…
Rare persistence techniques. Part 4 Also read about: Zabbix Agent, TimeProvider, COM Hijacking, WMICLNT. 5️⃣ Systemd Generator A Systemd Generator is an executa…
Rare persistence techniques. Part 3 Also read about: Zabbix Agent, TimeProvider, COM Hijacking. 4️⃣ WMICLNT This persistence technique is based on hijacking a D…