Topic
incident response
10 posts
- ArticleAug 2026 · 14 min
XSS2Shell: One Failed Login to PHP on the Server
CVE-2026-64638 is a reflected XSS on the WordPress login page — the finding most teams close as medium. Six gadgets sit between it and a PHP shell, and every one of them was already in core. Here is the chain, the log signatures, and what to harden after you patch.
- ArticleAug 2026 · 15 min
XSS2Shell: מניסיון התחברות כושל אחד ועד PHP על השרת
CVE-2026-64638 היא חולשת XSS מוחזר בעמוד ההתחברות של וורדפרס — בדיוק הממצא שרוב הצוותים סוגרים כבינוני. בין החולשה הזו לבין הרצת PHP על השרת עומדים שישה שלבים נוספים, וכולם כבר היו בליבת המערכת. הנה השרשרת המלאה, חתימות הזיהוי בלוגים, וההקשחה שצריך לעשות אחרי העדכון.
- BlogJul 2026 · 6 min
The 60-Minute Site: Phishing That Deletes Its Own Evidence
Cloudflare Drop publishes a site on a trusted workers.dev address with no account, then deletes it after an hour. That one-hour fuse burns your forensic evidence with it.
- ToolsAug 2025 · 2 min
Forti-DFIR: Open-Source Framework for Fortinet Forensics & Incident Response
At IONSEC, we’re proud to introduce Forti-DFIR — an open-source initiative created to give security teams the tools they need for forensic investigations and incident response in Fortinet environments.
- Case StudyJul 2025 · 8 min
When Research Meets Reality
How Threat-Actor Campaigns Cast a Shadow on Legitimate npm Binaries (and What IONSEC IR Sees in the wild)
- Case StudyJul 2025 · 8 min
How a Weaponized Zoom Installer Opened the Door for BlueNoroff
IONSEC investigates a BlueNoroff intrusion that began with a weaponized Zoom installer, combining deepfakes, social engineering and evasive scripting.
- Case StudyJul 2025 · 9 min
Iranian Threat Actor Hijacks DNS
קבוצת התקיפה האיראנית פתח אלקודס פרצה לרשם דומיינים ישראלי ושינתה רשומות DNS ו-MX של יותר מ-1,000 דומיינים, והפנתה אותם לשרת זדוני ולדף תעמולה.
- ArticleDec 2024 · 1 min
Why Malware Analysis Training is Vital: Lessons from Real-World Cyber Attacks
Picture this: airport metal detectors efficiently catch large, obvious weapons, but small components slip through unnoticed. Once inside, attackers assemble them into a complete weapon.
- NewsNov 2024 · 3 min
IONSEC at HackExpo 2024 – Breach at the Frontline
At HackExpo 2024, IONSEC CEO Nir Halfon shared practical strategies for responding to exploits in fintech first-party applications under live pressure.
- BlogMar 2024 · 8 min
SovaTeam - New State-Sponsored APT
How IONSEC and White-Hat traced the Sova Team threat actor through a ransom note to uncover a state-sponsored APT operating past strict security controls.