Cobalt Strike 4.8: (System) Call Me Maybe

Cobalt Strike 4.8 is now available. This release sees support for system calls, options to specify payload guardrails, a new token store, and more.   We had originally planned to get this release out late in 2022 but progress was stymied due to the 4.7.1 and 4.7.2 patch releases that we had to put out to […]

Read More…

Continue reading Cobalt Strike 4.8: (System) Call Me Maybe

Out Of Band Update: Cobalt Strike 4.7.2

Cobalt Strike 4.7.2 is now available. This is an out of band update to fix a remote code execution vulnerability that is rooted in Java Swing but which can be exploited in Cobalt Strike. Remote Code Execution Vulnerability I’d like to start by giving credit to Rio Sherri (0x09AL) and Ruben Boonen (FuzzySec) from the […]

Read More…

Continue reading Out Of Band Update: Cobalt Strike 4.7.2

Out Of Band Update: Cobalt Strike 4.7.1

Cobalt Strike 4.7.1 is now available. This is an out of band update to fix an issue discovered in the 4.7 release that was reported to be impacting users, and for which there was no workaround. We also took the opportunity to address a vulnerability that was reported shortly after the 4.7 release, along with […]

Read More…

Continue reading Out Of Band Update: Cobalt Strike 4.7.1

Cobalt Strike 4.7: The 10th Anniversary Edition

Cobalt Strike 4.7 is now available. This release sees support for SOCKS5, new options to provide flexibility around how BOFs live in memory, updates to how Beacon sleeps and a number of other changes that have been requested by our users. We’ve also given the user interface a bit of a refresh (including support for […]

Read More…

Continue reading Cobalt Strike 4.7: The 10th Anniversary Edition

Introducing alternative routing to prevent censorship of Proton apps

We’re announcing today a new anti-censorship system that can help users access our website if their government, ISP, or network administrator has blocked Proton services. The alternative routing feature is not yet deployed as of writing, but in t… Continue reading Introducing alternative routing to prevent censorship of Proton apps

Introducing DKIM key management, a new feature to protect against domain name impersonation

It is now harder for hackers and spammers to impersonate ProtonMail users that have custom domain email addresses. We have introduced the DKIM key management in beta, which allows you to manually rotate your DKIM keys. This is part of our continuing ef… Continue reading Introducing DKIM key management, a new feature to protect against domain name impersonation