Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
When Your Sandbox Fails
Threaded  |  Newest First  |  Oldest First
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
4/11/2019 | 12:36:34 PM
On Time
State sponsored actors and hackers have one huge advantage - time.  And the ability to think.  All they do is think about ways to hack and break into systems being as innovative as this article indicates.  New will always happen and they time on their hands to do more wrong, hence their attacks increase in sophistication.  We shall always be 5 minutes behind them at the least.  WE have daily chores, work and fighting infections among them while hunting down particulars of the infection real fast .... and they just have to think it up and release it.  No need to fight it for them.  They have the advantage, always have and always will. 

And again email delivery to user.  If you don't need it, don't read it, delete it.
ChadL196
50%
50%
ChadL196,
User Rank: Author
4/12/2019 | 12:55:18 PM
Sandbox evasion
Hi Kowsik,

Thanks for the read. Sandbox evasion is what we live and breathe. We've published our own work on that, and have dealt with the use cases you describe. Of course, some of it is dependant on the customer ensuring their analysis environment matches their own target environment. Hence we support gold images as analysis targets for ex. And tailoring of the localisation settings and VPN settings for outbound communication: https://www.vmray.com/cyber-security-blog/sandbox-evasion-techniques-part-1/


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-37457
PUBLISHED: 2021-07-25
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the SipRule field (stored).
CVE-2021-37458
PUBLISHED: 2021-07-25
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the primary phone field (stored).
CVE-2021-37459
PUBLISHED: 2021-07-25
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via the customer name field (stored).
CVE-2021-37460
PUBLISHED: 2021-07-25
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /planprop?id= (reflected).
CVE-2021-37461
PUBLISHED: 2021-07-25
Cross Site Scripting (XSS) exists in NCH Axon PBX v2.22 and earlier via /extensionsinstruction?id= (reflected).