🚨 We've added a new signature to our Suricata ruleset for the critical vulnerability CVE-2025-49113 in Roundcube, previously reproduced by @ptswarm.
This RCE vulnerability potentially exposes millions of hosts worldwide.
Update your rules now: rules.ptsecurity.com#Suricata
Guess who's back? 🎉 Our Suricata ruleset has found a new home at rules.ptsecurity.com! Enable source ptrules/open in Suricata-Update to stay ahead of threats.
One can get #Zabbix panel admin rights in one request with CVE-2022-23131. But you can detect it easily with our #suricata rule. We worked on possible rule bypasses and false positive rate
github.com/ptresearch/Att…
Rule updates: our #suricata rules detect all known Log4Shell CVE-2021-44228 bypasses for now. Also added a rule to detect a successful log4j exploitation!
Breaking news, the internet is under fire again! Releasing #suricata detection rule for log4j aka Log4Shell and CVE-2021-44228 as soon as possible. We will update the rule along with the new exploits and bypasses found.
github.com/ptresearch/Att…
Good: Use our #suricata rules to detect malicious attempts of the new CVE-2021-41773 #Apache HTTP Server dir traversal.
Better: Patch your apache
The best: Do both!
github.com/ptresearch/Att…
🔥 We have reproduced the fresh CVE-2021-41773 Path Traversal vulnerability in Apache 2.4.49.
If files outside of the document root are not protected by "require all denied" these requests can succeed.
Patch ASAP!
httpd.apache.org/security/vulne…
How to get a system shell on any windows version? Use #SystemNightmare exploit.
How to detect SystemNightmare usage in a network? Use our rules!
Oh, here they are: github.com/ptresearch/Att…
8K Followers 6K Following#InfoSec professional, husband & father of two (in random order). #BlueTeam #DFIR #APT #CTI #RedTeaming #BSidesZH (RT/Likes ≠ endorsement) 👀➡️#MalwareChallenge
853 Followers 13 FollowingFollow us for the latest malware findings and research reports from PT ESC, the Positive Technologies (@ptsecurity) Threat Intelligence Team.
1K Followers 20 FollowingOpen international cybersecurity specialist initiative. We collaborate on common problems and share knowledge. Mirror in telegram: https://t.co/HQWeyzwPZB
386 Followers 2K FollowingZenOpz is an MSSP dedicated to providing SMBs access to #infosec and #technology necessary to manage their data risks. Retweet/Follow is not an endorsement.