Akamai Diversity

Akamai Security Intelligence
& Threat Research

Or Katz

Or Katz

March 10, 2020 8:00 AM

Phishing Victims From a CDN's Point of View

Overview Being a Content Delivery Network (CDN) platform, sometimes you can see fractions of attacks on the wire. In this blog, we will focus on phishing websites that, while not being delivered by the Akamai platform, are referring to or redirecting victims to pages that are on Akamai's platform.

Danny Stern

Danny Stern

February 25, 2020 9:00 AM

How I Avoided A Recruiter Scam

Recruitment scams are a serious, but often overlooked risk to job seekers. Those responsible for these schemes often play on the victim's stress levels or professional ego, by using authority to offer something that could be life changing, often with large salaries. I've personally experienced a recruitment scam. In this post, we'll explore the scam that targeted me, and the steps I took that prevented me from becoming a victim.

Amanda Fakhreddine

Amanda Fakhreddine

February 19, 2020 6:00 AM

State of the Internet / Security Volume 6, Issue 1

Happy New Year! It's February now, so we've made, and most likely have broken, all of those New Year's Resolutions that we vowed to keep. As we look forward to the rest of 2020, the staff that produces the State of the Internet / Security report really only has one resolution -- evolve.

Daniel Abeles

Daniel Abeles

January 20, 2020 9:00 AM

Abusing the Service Workers API

The Service Worker web API is a powerful new API for web browsers. During our research, we have found several ways attackers can leverage this API to enhance their low-to-medium risk findings into a powerful and meaningful attack. By abusing this API, an attacker can also leave his footprint in the victim's browser and potentially leak sensitive information. By the end of this post, you will have the basics

Akamai

Akamai

January 13, 2020 12:00 PM

HTTP Cache Poisoning Advisory

Summary On January 14, 2020, CERT CC published an advisory warning of the potential use of Content Delivery Networks (CDNs) to cache malicious traffic. Akamai acknowledges this issue and has been aware of similar research in the past. This advisory highlights a reflected XSS vulnerability in origin web applications that exists whether or not a CDN is involved, exacerbated by having responses cached. Site operators should be aware that HTTP

Samuel Erb

Samuel Erb

December 20, 2019 9:00 AM

Do Not Trust User Input While Rendering PDFs

I recently had the opportunity to team up with three other security researchers (Brett Buerhaus, Cody Brocious (Daeken), Olivier Beg (Smiegles)) to examine the usage of PDF renders on the Internet.

Or Katz

Or Katz

December 17, 2019 9:00 AM

Access and Threat Insights: Thanksgiving

Overview Thanksgiving in the United States is considered by many to mark a good time of year to gain insight into enterprise access and threats. From an enterprise point of view, Thanksgiving is when many American users will be on vacation, but may still working from home, in some capacity. It's interesting to see users' access patterns as they pertain to enterprise applications, such as email or other SaaS platforms,

Larry Cashdollar

Larry Cashdollar

December 11, 2019 9:00 AM

Exploring Legacy Unix Security Issues

Sometimes after looking at web application security, IoT botnets, and various malware I long for the pre-2000 hacking days. Where, instead of looking for XSS or SQL injection vulnerabilities, you would be hunting for server-side vulnerabilities. This summer, I was gifted an SGI Indy R5000. I'd mentioned on Twitter a while back that I'd love to have an IRIX system in my lab, since this was the system I'd discovered

Amanda Fakhreddine

Amanda Fakhreddine

December 4, 2019 6:00 AM

2019: A Year In Review with State of the Internet/ S ...

December is typically a time where many people and businesses take a moment to reflect on everything that happened during the last 12 months. Everything - the good, the bad and the ugly.