19 December 2018

In this post, we describe the new RDP man-in-the-middle and library project we developed and open sourced. Our MITM features a file stealer, a clipboard stealer and the ability to watch RDP sessions either live or after the fact. It is used as part of our RDP honeypot. In this post, we also describe an incident with a malicious user that infected our honeypot.

May 17, 2018

On Tuesday, we released the details of RCE vulnerability affecting Spring Data (CVE-2018-1273). We are now repeating the same exercise for a similar RCE vulnerability in Spring Security OAuth2 (CVE-2018-1260).

May 15, 2018

This February, we ran a Find Security Bugs scan on over at least one hundred components from the Spring Framework. Here is how these vulnerabilities were found, followed by a thorough review of the proposed fix.

April 26, 2018

Red Onions in WaterThis blog is the outcome of my 4 months of internship at GoSecure. I will describe two internal projects that we have developed to gather all kinds of interesting and valuable data. The first project aimed at gathering data on .onion sites—known as the Darknet—while the second one focused at gathering data on sites like Pastebin, GitHub’s gists and Dumpz.