Get a Pentest and security assessment of your IT network.

Cyber Security

Microsoft shares CodeQL queries to scan code for SolarWinds-like implants

Microsoft has open-sourced CodeQL queries that developers can use to scan source code for malicious implants matching the SolarWinds supply-chain attack. Developers can scan their source codebase for functionality or syntactic code elements that match those used by the malicious implants from the attack. Microsoft warns that some of these queries can find similar behavior in benign code, so it is essential to manually review any detections to ensure they are not false positives. Microsoft: “We are open sourcing the queries that we used in this investigation so that other organizations may perform a similar analysis”””

Source: https://www.bleepingcomputer.com/news/security/microsoft-shares-codeql-queries-to-scan-code-for-solarwinds-like-implants/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security