Headline
CVE-2022-39197: Releases Archives - Cobalt Strike Research and Development
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed).
Development, Releases 2 min
Out Of Band Update: Cobalt Strike 4.7.1
Cobalt Strike 4.7.1 is now available. This is an out of band update to fix an issue discovered in the 4.7 release that was reported
Read More
Development, Releases 12 min
Cobalt Strike 4.7: The 10th Anniversary Edition
Cobalt Strike 4.7 is now available. This release sees support for SOCKS5, new options to provide flexibility around how BOFs live in memory, updates to
Read More
Development, Releases 1 min
Out Of Band Update: Cobalt Strike 4.6.1
Cobalt Strike 4.6.1 is now available. This is an out of band update to fix a few issues that were discovered in the 4.6 release
Read More
Development, Releases 4 min
Cobalt Strike 4.6: The Line In The Sand
Cobalt Strike 4.6 is now available. As I mentioned in the recent Roadmap Update blog post, this isn’t a regular release, as it mostly focuses
Read More
Development, Releases 3 min
Cobalt Strike 4.5: Fork&Run – you’re “history”
Cobalt Strike 4.5 is now available. This release sees new options for process injection, updates to the sleep mask and UDRL kits, evasion improvements and
Read More
Releases 2 min
Cobalt Strike 3.0 – Advanced Threat Tactics
Cobalt Strike’s mission is to help security professionals emulate “advanced threat tactics” during their engagements. I’ve executed on this since the product’s 2012 release. Cobalt
Read More
Related news
The fix was developed at a running pace as Cobalt Strike is essential to Red Team operations
HelpSystems, the company behind the Cobalt Strike software platform, has released an out-of-band security update to address a remote code execution vulnerability that could allow an attacker to take control of targeted systems. Cobalt Strike is a commercial red-team framework that's mainly used for adversary simulation, but cracked versions of the software have been actively abused by ransomware