⚠️ PT ESC experts have detected attempts to exploit the CVE-2025-24071 vulnerability
⚠️ PT ESC experts have detected attempts to exploit the CVE-2025-24071 vulnerability The vulnerability CVE-2025-24071, affecting a wide range of Windows operati…
⚠️ PT ESC experts have detected attempts to exploit the CVE-2025-24071 vulnerability The vulnerability CVE-2025-24071, affecting a wide range of Windows operati…
A complex password won't help 📮 The practice of the PT ESC IR information security incident response team shows that attackers, upon gaining access to companies…
😐 “Why aren't you answering?”, or The Story of How to Steal a Telegram Account Without Registration or SMS Recently we published an article about the most popul…
Roots of the CVE-2024-30085 Vulnerability 🌳 Back in September of last year, we at ESC-VR successfully reproduced an exploit for CVE-2024-30085 — a vulnerability…
Net group "babyk" /add During the investigation of one of the incidents, we discovered the exploitation of the CVE-2024-37085 vulnerability. It allows…
Where can the history of PowerShell commands be found? 🧐 Surely the first things that come to mind are Windows logs and the ConsoleHost_history.txt file, but th…
😏 Exclusively for Escalator, the ESC-VR team shares details about the vulnerability (CVE-2024-43629) that we found in the Desktop Window Manager component, allo…
⚠️ OWOWAsome module, or IIS kOWOWAren Researchers reported on the malicious IIS module Owowa, designed to intercept user credentials, back in 2021. And in 2022…
Where to look for network indicators of compromise on Windows? For example, in the DNS cache 💡 The DNS cache is a mechanism for caching records that map domain…
☝️ In addition to Windows logs, another interesting artifact provided by a popular antivirus protection tool helped us in investigating the activity described i…
ℹ️ Exfiltration using PowerShell/C# During an incident investigation, while analyzing Windows event logs on one of the compromised hosts, we discovered that a P…
Exfiltration on an industrial scale 😐 The APT group Cloud Atlas has been attacking Russian companies since 2019, engaging in espionage and theft of confidential…