Ir al contenido principal
Investigación de Seguridad Avanzada [email protected]

DEFION Research Labs

Investigación original de vulnerabilidades, divulgación responsable y resultados de competiciones.

34
Publicaciones
9
Pwn2Own
CVE
Divulgaciones propias
NMR
No More Ransom
Contacto seguro con research

Envíe hallazgos sensibles a [email protected] usando nuestra clave PGP o certificado S/MIME.

Huella PGP: 4895 49D1 5C51 819E 520B  28E9 C858 95B4 5B49 39BD

Inteligencia de Amenazas

Más que investigación: inteligencia de amenazas diaria

Además de la investigación técnica, DEFION monitoriza continuamente el panorama de amenazas para organizaciones en NL, BE y ES. Nuestra unidad de Threat Intelligence sigue más de 40 fuentes, rastrea más de 30 grupos activos de ransomware y traduce las amenazas geopolíticas en riesgos concretos para tu sector.

Ver nuestra Threat Intelligence
30+
Grupos de ransomware
40+
Fuentes monitorizadas
Europa
Inteligencia sectorial
24/7
Actores APT

Toda la investigación

Malware
25 July 2024

DoNex/DarkRace Ransomware Decryptor

Leer →
Windows
14 June 2024

CVE-2024-20693: Windows cached code signature manipulation

Leer →
iOS & macOS
5 April 2024

Bringing process injection into view(s): exploiting all macOS apps using nib fil...

Leer →
iOS & macOS
13 October 2023

Don't Talk All at Once! Elevating Privileges on macOS by Audit Token Spoofing

Leer →
Windows
28 September 2023

Getting SYSTEM on Windows in style

Leer →
Malware
5 April 2023

Technical analysis of the Genesis Market

Leer →
iOS & macOS
13 January 2023

Bad things come in large packages: .pkg signature verification bypass on macOS

Leer →
Pwn2Own
17 October 2022

Pwn2Own Miami 2022: ICONICS GENESIS64 Arbitrary Code Execution

Leer →
Pwn2Own
14 September 2022

Pwn2Own Miami 2022: Unified Automation C++ Demo Server DoS

Leer →
Pwn2Own
8 September 2022

Pwn2Own Miami 2022: AVEVA Edge Arbitrary Code Execution

Leer →
iOS & macOS
12 August 2022

Process injection: breaking all macOS security layers with a single vulnerabilit...

Leer →
Pwn2Own
22 July 2022

Pwn2Own Miami 2022: Inductive Automation Ignition Remote Code Execution

Leer →
Pwn2Own
19 July 2022

Pwn2Own Miami 2022: OPC UA .NET Standard Trusted Application Check Bypass

Leer →
Cryptography
3 February 2022

CoronaCheck App TLS certificate vulnerabilities

Leer →
iOS & macOS
21 December 2021

Sandbox escape + privilege escalation in StorePrivilegedTaskService

Leer →
App Security
14 December 2021

Proctorio Chrome extension Universal Cross-Site Scripting

Leer →
Pwn2Own
23 August 2021

Zoom RCE from Pwn2Own 2021

Leer →
iOS & macOS
7 October 2020

iOS VPN support: 3 different bugs

Leer →
iOS & macOS
1 July 2020

Sign in with Apple - authentication bypass

Leer →
DevOps
30 January 2020

Jenkins - authentication bypass

Leer →
Cryptography
25 November 2019

DNS rebinding for HTTPS

Leer →
DevOps
4 July 2019

Spring Security - insufficient cryptographic randomness

Leer →
Network
14 August 2018

XenServer - path traversal leading to authentication bypass

Leer →
App Security
19 July 2018

Volkswagen Auto Group MIB infotainment system - unauthenticated remote code exec...

Leer →
DevOps
12 July 2017

NAPALM - command execution on NAPLM controller from host

Leer →
DevOps
25 April 2017

MySQL Connector/J - Unexpected deserialisation of Java objects

Leer →
DevOps
9 January 2017

Ansible - command execution on Ansible controller from host

Leer →
Network
10 November 2016

Observium - unauthenticated remote code execution

Leer →
Cryptography
18 August 2016

cSRP/srpforjava - obtaining of hashed passwords

Leer →
Cryptography
30 June 2016

StartEncrypt - obtaining valid SSL certificates for unauthorized domains

Leer →

¿Interesado en nuestra investigación?

[email protected]