Ga naar hoofdinhoud
Geavanceerd Beveiligingsonderzoek [email protected]

DEFION Research Labs

Origineel kwetsbaarheidsonderzoek, responsible disclosure en wedstrijdresultaten.

34
Publicaties
6
Pwn2Own
CVE
Eigen disclosures
NMR
No More Ransom
Threat Intelligence

Meer dan research: dagelijkse dreigingsintelligence

Naast technisch onderzoek monitort DEFION continu het dreigingslandschap voor organisaties in NL, BE en ES. Onze Threat Intelligence unit volgt 40+ bronnen, trackt meer dan 30 actieve ransomware-groepen en vertaalt geopolitieke dreigingen naar concrete risico's voor jouw sector.

Van wekelijkse briefings en MITRE ATT&CK heatmaps tot klantspecifieke dreigingsanalyses en real-time IoC-feeds. Intelligence die niet van buiten wordt ingekocht, maar voortkomt uit onze eigen SOC-data en DFIR-cases.

Bekijk onze Threat Intelligence
30+
Ransomware-groepen
40+
Bronnen gemonitord
Europa
Sector intelligence
24/7
APT-actoren

Alle artikelen

Malware
25 juli 2024

DoNex/DarkRace Ransomware Decryptor

Lees →
Windows
14 juni 2024

CVE-2024-20693: Windows cached code signature manipulation

Lees →
iOS & macOS
5 april 2024

Bringing process injection into view(s): exploiting all macOS apps using nib fil...

Lees →
iOS & macOS
13 oktober 2023

Don't Talk All at Once! Elevating Privileges on macOS by Audit Token Spoofing

Lees →
Windows
28 september 2023

Getting SYSTEM on Windows in style

Lees →
Malware
5 april 2023

Technical analysis of the Genesis Market

Lees →
iOS & macOS
13 januari 2023

Bad things come in large packages: .pkg signature verification bypass on macOS

Lees →
Pwn2Own
17 oktober 2022

Pwn2Own Miami 2022: ICONICS GENESIS64 Arbitrary Code Execution

Lees →
Pwn2Own
14 september 2022

Pwn2Own Miami 2022: Unified Automation C++ Demo Server DoS

Lees →
Pwn2Own
8 september 2022

Pwn2Own Miami 2022: AVEVA Edge Arbitrary Code Execution

Lees →
iOS & macOS
12 augustus 2022

Process injection: breaking all macOS security layers with a single vulnerabilit...

Lees →
Pwn2Own
22 juli 2022

Pwn2Own Miami 2022: Inductive Automation Ignition Remote Code Execution

Lees →
Pwn2Own
19 juli 2022

Pwn2Own Miami 2022: OPC UA .NET Standard Trusted Application Check Bypass

Lees →
Cryptography
3 februari 2022

CoronaCheck App TLS certificate vulnerabilities

Lees →
iOS & macOS
21 december 2021

Sandbox escape + privilege escalation in StorePrivilegedTaskService

Lees →
App Security
14 december 2021

Proctorio Chrome extension Universal Cross-Site Scripting

Lees →
Pwn2Own
23 augustus 2021

Zoom RCE from Pwn2Own 2021

Lees →
iOS & macOS
7 oktober 2020

iOS VPN support: 3 different bugs

Lees →
iOS & macOS
1 juli 2020

Sign in with Apple - authentication bypass

Lees →
DevOps
30 januari 2020

Jenkins - authentication bypass

Lees →
Cryptography
25 november 2019

DNS rebinding for HTTPS

Lees →
DevOps
4 juli 2019

Spring Security - insufficient cryptographic randomness

Lees →
Network
14 augustus 2018

XenServer - path traversal leading to authentication bypass

Lees →
App Security
19 juli 2018

Volkswagen Auto Group MIB infotainment system - unauthenticated remote code exec...

Lees →
DevOps
12 juli 2017

NAPALM - command execution on NAPLM controller from host

Lees →
DevOps
25 april 2017

MySQL Connector/J - Unexpected deserialisation of Java objects

Lees →
DevOps
9 januari 2017

Ansible - command execution on Ansible controller from host

Lees →
Network
10 november 2016

Observium - unauthenticated remote code execution

Lees →
Cryptography
18 augustus 2016

cSRP/srpforjava - obtaining of hashed passwords

Lees →
Cryptography
30 juni 2016

StartEncrypt - obtaining valid SSL certificates for unauthorized domains

Lees →