Blog
Threat research, vulnerability breakdowns, and practical security guidance from Clear Infosec.
What you will find here
Threat Intelligence Bulletins
Weekly roundups of new CVEs, active exploits, and defensive guidance.
Case Studies
Real engagements and measurable outcomes from our security work.
White Papers
In-depth research and practical frameworks for security and compliance teams.
Blogs
Threat research, vulnerability breakdowns, and practical guidance.
-

Recent Ransomware attacks 2022
Ransomware attacks have become very high in recent days. The ongoing attacks cause losses to lots of organizations. Knowledge of Ransomware and its anatomy…
-

ToddyCat APT unveiled
Multiple threats detected from December 2020 against high-profile entities in Europe and Asia are finally traced to be responsible by a new Advanced Persistent…
-

Ransomware As A Service
Ransomware as a service is a business model where the customers or the malicious party use the ransomware developed by the experienced hacker. They…
-

Ransomware Blockchain
This blog will see whether it is possible to use the blockchain concept to track ransomware attackers or prevent such attacks. I have explained…
-

Follina – ZeroDay hole in MS Office
Microsoft has confirmed a Remote Code Execution (RCE) vulnerability in Microsoft Support Diagnostic Tool (MSDT) which is expected to be exploited since April, at…
-

WINDOWS LSA Spoofing Vulnerability
Microsoft released a patch for Windows Local Security Authority (LSA) spoofing recently. This was one among the 74 security flaws reported to be fixed…
-

Do you know about Denonia?
Malware that targets AWS Lambda Environments A first-of-its-kind malware that is specifically designed to execute in an AWS Lambda environment has been discovered by…
-

Microsoft Autopatch
Everyone might have already known that Microsoft announced a feature Windows Autopatch, which will be released in July 2022. This blog is about this…
-

What is Spring4Shell?
Spring framework is found to have a Remote Code Execution (RCE) flaw. This vulnerability, if exploited successfully, will let the attacker take control of…
-

Dirty Pipe – Privilege Escalation Vulnerability in Linux
Linux is found to have yet another severe privilege escalation vulnerability (CVE 2022-0847) in kernel version 5.8 and above. This vulnerability is allowed bad…