OVERPASS and S4GET now have public proof-of-concept code. How to assess the change in threat, investigate exposure and set useful priorities without overstating the evidence.
Two exploited zero-days, a foothold on the gateway, and a response that must reach into the internal network. A CTI and SOC reading of the September NetScaler disclosures.
EDR killers have become a standard stage of ransomware intrusions. A SOC look at how BYOVD works, what it leaves behind, and which detections actually fire in time.