Use of CSS stuffing as an obfuscation technique?, (Fri, Nov 21st)

From time to time, it can be instructive to look at generic phishing messages that are delivered to one’s inbox or that are caught by basic spam filters. Although one usually doesn’t find much of interest, sometimes these little excursions into what should be a run-of-the-mill collection of basic, commonly used phishing techniques can lead one to find something new and unusual. This was the case with one of the messages delivered to our handler inbox yesterday…

Continue reading Use of CSS stuffing as an obfuscation technique?, (Fri, Nov 21st)

Posted in Uncategorized

Oracle Identity Manager Exploit Observation from September (CVE-2025-61757), (Thu, Nov 20th)

Searchlight Cyber today released a blog detailing CVE-2025-61757, a vulnerability they reported to Oracle. Oracle released a patch for the vulnerability as part of its October Critical Patch Update, which was released on October 21st.

Continue reading Oracle Identity Manager Exploit Observation from September (CVE-2025-61757), (Thu, Nov 20th)

Posted in Uncategorized

Unicode: It is more than funny domain names., (Wed, Nov 12th)

When people discuss the security implications of Unicode, International Domain Names (IDNs) are often highlighted as a risk. However, while visible and often talked about, IDNs are probably not what you should really worry about when it comes to Unicode. There are several issues that impact application security beyond confusing domain names.

Continue reading Unicode: It is more than funny domain names., (Wed, Nov 12th)

Posted in Uncategorized