SecureThinkLab logo
  • About 
  • Blog 
  • Tags 
  •    Toggle theme
    •   Light
    •   Dark
    •   Auto
  •  
    •   Light
    •   Dark
    •   Auto
  1. Home
  2. Blog

Blog

Multiple CVEs in Cisco EPNM and Prime Infrastructure

September 23, 2025 • 5 min read • CVE

Multiple CVEs in Cisco EPNM and Prime Infrastructure

During our research activities, we identified multiple vulnerabilities in the webbased management interface of Cisco Evolved Programmable Network Manager EPNM and Cisco Prime Infrastructure. These vulnerabilities could allow a remote attacker, who is authenticated and has limited privileges, to execute malicious code on the client side, obtain sensitive information, or upload arbitrary files to a vulnerable system.

CVE-2025-20269: Cisco EPNM and Prime Infrastructure Arbitrary File Retrieval

August 27, 2025 • 2 min read • CVE

CVE-2025-20269: Cisco EPNM and Prime Infrastructure Arbitrary File Retrieval

CVE202520269 is a vulnerability in the webbased management interface of Cisco Evolved Programmable Network Manager EPNM and Cisco Prime Infrastructure. It allows a remote, authenticated, lowprivileged attacker to retrieve arbitrary files from the underlying file system by sending crafted HTTP requests. Cisco has released software updates to address the issue, and no workarounds are available.

GodFather Android Malware Analysis

March 14, 2025 • 18 min read • Malware

GodFather Android Malware Analysis

GodFather is an Android malware that was first identified in mid 2023 and quickly attracted the attention of security experts because of its advanced capabilities and modular structure. Its design highlights a significant evolution from its predecessors, exploiting sophisticated techniques to circumvent security measures and infect Android devices.In this article, we will explore how this version of the malware communicates with the C2 server, a critical component that allows attackers to manage the malware in real time and receive stolen data....

CVE-2024-34456: Trend Micro Antivirus One Dylib Injection

May 6, 2024 • 6 min read • macOS

CVE-2024-34456: Trend Micro Antivirus One Dylib Injection

During a red teaming activity, we gained access to a company MacBook; the Trend Micro Antivirus One software was running and prevented us from running our tools without being detected.So, I analyzed the software and found a misconfiguration that allow to inject a custom dylib into the application process.The CVE202434456 has been assigned to this issue, affecting Trend Micro Antivirus One version 3.10.3 and below. I reported it on February 6, 2024, and according to Trend Micro, following its resolution, the public disclosure was scheduled for today, May 6, 2024....

Gold Pickaxe iOS Technical Analysis: IPA Overview and C2 Communication Startup

April 19, 2024 • 12 min read • malwares

Gold Pickaxe iOS Technical Analysis: IPA Overview and C2 Communication Startup

In February 2024 GroupIB wrote a blog post about a mobile Trojan developed by a Chinesespeaking cybercrimine group called Gold Pickaxe.This malware targets both iOS and Android users in the Asia Pacific region in order to collect identity documents, SMS, pictures and other data related to the compromised phones.The malware communicates with the C2 using two protocolsThe websocket protocol used to listen for incoming commands The HTTP protocol used to send information and data to the C2 In this article we are going to analyse the IPA file, and then describe how the malware connects to the C2 websocket server....

AMOS (Atomic macOS Stealer) Analysis

March 1, 2024 • 11 min read • malwares

AMOS (Atomic macOS Stealer) Analysis

Hello everybody, this is my first macOS malware analysis, I took a sample from malwarebazaar and tried to reverse it, the sample was uploaded by Cryptolaemus1 on 14 Feb 2024.While analysing the stage two, it was clear that the sample is a variant of Atomic Stealer.Atomic Stealer, as reported by SentinelOne is a macOS info stealer sold on Telegram, able to grab system information, account credential, browser data, session cookies and crypto wallets....

Rustware Part 3: Dynamic API resolution (Windows)

November 20, 2023 • 11 min read • rust

Rustware Part 3: Dynamic API resolution (Windows)

In the previous blog post we have seen how to perform a shellcode process injection by finding a target process PID using several WinAPIs, in that case all the WinAPIs were called directly. Usually malwares resolve the WinAPI address at runtime in order to hide malicious behaviours during static analysis.I have to thank Jacopo for his feedbacks, he helped me to improve the code.In this blog post we will see how to use two wellknown WinAPIs to dynamically resolve the WinAPIs Address GetModuleHandle used to get a module address and GetProcessAddress used to get a WinAPI address....

Rustware Part 2: Process Enumeration Development (Windows)

November 6, 2023 • 9 min read • rust

Rustware Part 2: Process Enumeration Development (Windows)

In the previous blog post we have seen how to develop a Shellcode Process Injection in Rust; the described Process Injection flow relies on several WinAPIs OpenProcess used to open a handle to the target process, then VirtualAllocEx was used to allocate a new readable and writable region of memory into the target process, WriteProcessMemory wrote the shellcode into the new allocated memory, then VirtualProtectEx was used to change the new allocated memory protection to readable and executable in order to allow the CreateRemoteThread to execute the shellcode contained into the new allocated memory in the target process....

Rustware Part 1: Shellcode Process Injection Development (Windows)

October 27, 2023 • 11 min read • rust

Rustware Part 1: Shellcode Process Injection Development (Windows)

Malware development is essential when performing activities like Red Teaming, Adversary Emulation and Network Penetration Testing, the operator can use custom malwares to perform various tasks based on the specific situation. At the same time, analyzing Malwares is useful to learn how malwares work and how to detect them, in order to defend our companies from threat actors. For these reasons I studied several books and courses about Windows Internals, Malware Development and Malware Analysis....

     
Copyright © 2025 SecureThinkLab All rights reserved.
SecureThinkLab
Code copied to clipboard