Eric Forte

Eric Forte

Senior Software Engineer

Abonnieren
Artikel von Eric Forte
Not another Log4Shell: inside the Log4j 2 deserialization allowlist bypass
Security Labs

Not another Log4Shell: inside the Log4j 2 deserialization allowlist bypass

We reproduced this java deserialization vulnerability against official Log4j 2.26.1 JARs. Getting to command execution took two more things that Log4j itself does not ship. Here is how the bypass works, which versions carry it, and what to hunt for.

Ruben Groenewoud
Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild
Security Labs

Copy Fail and DirtyFrag: Linux Page Cache Bugs in the Wild

This research analyzes the Linux kernel privilege escalation vulnerabilities Copy Fail and DirtyFrag, which exploit subtle page cache corruption bugs to create reliable paths to root access. Additionally, Elastic Security Labs is releasing detection logic for these vulnerabilities.

Ruben Groenewoud
The Engineer's Guide to Elastic Detections as Code
Security Labs

The Engineer's Guide to Elastic Detections as Code

This post details the latest evolution of Elastic Security's Detections as Code (DaC) framework, including its development timeline, current feature highlights, and tailored implementation examples.

Eric Forte
Cups Overflow: When your printer spills more than Ink
Security Labs

Cups Overflow: When your printer spills more than Ink

Elastic Security Labs discusses detection and mitigation strategies for vulnerabilities in the CUPS printing system, which allow unauthenticated attackers to exploit the system via IPP and mDNS, resulting in remote code execution (RCE) on UNIX-based systems such as Linux, macOS, BSDs, ChromeOS, and Solaris.

Mika Ayenson
Storm on the Horizon: Inside the AJCloud IoT Ecosystem
Security Labs

Storm on the Horizon: Inside the AJCloud IoT Ecosystem

Wi-Fi cameras are popular due to their affordability and convenience but often have security vulnerabilities that can be exploited.

Mark Mager
Now in beta: New Detection as Code capabilities
Security Labs

Now in beta: New Detection as Code capabilities

Mika Ayenson
Google Cloud for Cyber Data Analytics
Security Labs

Google Cloud for Cyber Data Analytics

This article explains how we conduct comprehensive cyber threat data analysis using Google Cloud, from data extraction and preprocessing to trend analysis and presentation. It emphasizes the value of BigQuery, Python, and Google Sheets - showcasing how to refine and visualize data for insightful cybersecurity analysis.

Terrance DeJesus
Streamlining ES|QL Query and Rule Validation: Integrating with GitHub CI
Security Labs

Streamlining ES|QL Query and Rule Validation: Integrating with GitHub CI

ES|QL is Elastic's new piped query language. Taking full advantage of this new feature, Elastic Security Labs walks through how to run validation of ES|QL rules for the Detection Engine.

Mika Ayenson