LDAP Passback
LDAP Passback and Why We Harp on Passwords

LDAP passback exploits are easy when companies fail to change default passwords on network devices[…]

SonicWall
SonicWall Patches Three Zero-Day Vulnerabilities

Cybersecurity company SonicWall has released patches for three zero-day vulnerabilities that are currently being exploited.

Emblem of the Foreign Intelligence Service of the Russian Federation
NSA, FBI, CISA Statement on Russian SVR Activity

The US government is warning businesses to beware of vulnerabilities being exploited by the Russian[…]

Remediating Account Enumeration Vulnerabilities
Remediating Account Enumeration Vulnerabilities

Account enumeration reveals to an attacker whether or not he or she has valid user[…]

The rdp_web_login Metasploit Module in Use
New Metasploit Module: Microsoft Remote Desktop Web Access Authentication Timing Attack

Raxis team member Matt Dunn has uncovered a vulnerability in Microsoft’s Remote Desktop Web Access[…]

How to Pull Off a Mousejacking Attack
How to Pull Off a Mousejacking Attack

Raxis demonstrates how to conduct a mousejacking attack as part of a penetration test.

Penguin with red cross
Sudo Privilege Escalation Vulnerability Discovered

Qualys has discovered and reported a serious vulnerability (CVE-2021-3156) affecting the sudo utility. Patches are[…]

Cisco with bandaids
Cisco Patches Critical Security Vulnerabilities

Cisco releases patches for some critical and high-severity vulnerabilities.

Cisco Smart Install
Why you should turn off Cisco Smart Install now

Cisco Smart Install is handy for admins, but a security risk if it’s improperly managed.

Broadcast Poisoning
AttackTek: How to Launch a Broadcast Resolution Poisoning and SMB Relay Attack

An easy, effective way to test corporate networks is with broadcast poisoning and SMB relay[…]

Notice: Authorized Personnel Only
Why Worry About Unauthorized Entry?

What’s the worst that can happen if a hacker breaks through your physical defenses and[…]