Explains the vulnerability MCPosion (CVE-2025-54136) discovered in the AI code editor "Cursor". We have identified flaws in the trust model and summarized the methods and countermeasures that can lead to remote code execution (RCE) by exploiting MCP settings. We are now publishing methods to protect ourselves from new threats lurking in AI-assisted development environments. |Colorkrew Security
OSINT Explains Admin Page Identification and SQL Injection Attack Flow, WAF Evasion Methods, Detection Methods, and Defense-in-Depth Practices|Colorkrew Security
Explains the threat of new malware PROMPTFLUX and PROMPTSTEAL, which exploit generative AI such as Gemini to autonomously mutate and generate instructions. Organize attack methods and practical countermeasures based on GTIG reports|Colorkrew Security
Explains the latest attack methods of Winos 4.0 and HoldingHands RAT used by the Chinese hacker group Silver Fox. Organized sophisticated intrusions and practical measures targeting Japanese companies|Colorkrew Security
Streamline security operations with AWS Config, a configuration monitoring service from AWS. By working with Colorkrew's SOC, you can enhance your monitoring, automation, and response! |Colorkrew Security
Want to leverage AWS Security Hub to enhance your cloud security? In this article, we will explain in detail the secrets of advanced security operations by linking with SOCs. Learn how automated incident response and compliance checks can improve your company's security level. Together with Colorkrew's professional services, we support the construction of a safe and secure AWS environment. |Colorkrew Security
Learn more about how AWS GuardDuty can be leveraged to streamline your organization's security operations. We also introduced threat detection capabilities, integration with other security services on AWS, and GuardDuty's pricing plans. This is a practical guide for those who want to reduce the burden of SOC operations and strengthen security measures. |Colorkrew Security
This section provides a detailed explanation of AWS WAF, which is a basic security measure for AWS environments. Introduce rule settings to protect web applications from injection and DDoS attacks, enhanced defenses with AWS Shield integration, and cost control points. Learn how to operate AWS WAF effectively and improve your security in the cloud. |Colorkrew Security
Hello. I'm Jaeho Yoon, who works as an engineer on the MSP team. After the cold winter, you can feel the warmth of the gorgeous cherry blossoms blooming, and you can feel that spring has arrived. After the graduation season has passed and April arrives, a new life begins with half worry and half expectation in many places such as universities and companies. I also remember two years ago, I couldn't sleep because I was excited about the new life of Japan. ...