Blog

Threat research, vulnerability breakdowns, and practical security guidance from Clear Infosec.

What you will find here

Threat Intelligence Bulletins

Weekly roundups of new CVEs, active exploits, and defensive guidance.

Case Studies

Real engagements and measurable outcomes from our security work.

White Papers

In-depth research and practical frameworks for security and compliance teams.

Blogs

Threat research, vulnerability breakdowns, and practical guidance.

  • Recent Ransomware attacks 2022

    Recent Ransomware attacks 2022

    Ransomware attacks have become very high in recent days. The ongoing attacks cause losses to lots of organizations. Knowledge of Ransomware and its anatomy…

    Read more

  • ToddyCat APT unveiled

    ToddyCat APT unveiled

    Multiple threats detected from December 2020 against high-profile entities in Europe and Asia are finally traced to be responsible by a new Advanced Persistent…

    Read more

  • Ransomware As A Service

    Ransomware As A Service

    Ransomware as a service is a business model where the customers or the malicious party use the ransomware developed by the experienced hacker. They…

    Read more

  • Ransomware Blockchain

    Ransomware Blockchain

    This blog will see whether it is possible to use the blockchain concept to track ransomware attackers or prevent such attacks. I have explained…

    Read more

  • Follina – ZeroDay hole in MS Office

    Follina – ZeroDay hole in MS Office

    Microsoft has confirmed a Remote Code Execution (RCE) vulnerability in Microsoft Support Diagnostic Tool (MSDT) which is expected to be exploited since April, at…

    Read more

  • WINDOWS LSA Spoofing Vulnerability

    WINDOWS LSA Spoofing Vulnerability

    Microsoft released a patch for Windows Local Security Authority (LSA) spoofing recently. This was one among the 74 security flaws reported to be fixed…

    Read more

  • Do you know about Denonia?

    Do you know about Denonia?

    Malware that targets AWS Lambda Environments A first-of-its-kind malware that is specifically designed to execute in an AWS Lambda environment has been discovered by…

    Read more

  • Microsoft Autopatch

    Microsoft Autopatch

    Everyone might have already known that Microsoft announced a feature Windows Autopatch, which will be released in July 2022. This blog is about this…

    Read more

  • What is Spring4Shell?

    What is Spring4Shell?

    Spring framework is found to have a Remote Code Execution (RCE) flaw. This vulnerability, if exploited successfully, will let the attacker take control of…

    Read more

  • Dirty Pipe – Privilege Escalation Vulnerability in Linux

    Dirty Pipe – Privilege Escalation Vulnerability in Linux

    Linux is found to have yet another severe privilege escalation vulnerability (CVE 2022-0847) in kernel version 5.8 and above. This vulnerability is allowed bad…

    Read more