GootLoader Uses Malformed ZIPs to Evade Detection
The JavaScript-based malware loader GootLoader has adopted a novel anti-analysis technique that abuses malformed ZIP archives to evade security detection w...
Expert analysis, threat intelligence, and practical guidance from Red Secure Tech's security specialists — covering penetration testing, vulnerability assessment, incident response, and secure development for UK businesses.
The JavaScript-based malware loader GootLoader has adopted a novel anti-analysis technique that abuses malformed ZIP archives to evade security detection while still functioning seamlessly on Windows...
Read Full ArticleThe JavaScript-based malware loader GootLoader has adopted a novel anti-analysis technique that abuses malformed ZIP archives to evade security detection w...
Most teams already run scanners.Many still miss XSS.That’s because XSS is rarely a simple input problem.It’s a data-flow and context problem.Re...
A China-nexus advanced persistent threat (APT), tracked as UAT-8837 by Cisco Talos, has been observed targeting critical infrastructure sectors in North Am...
An Amazon Web Services (AWS) CodeBuild critical misconfiguration could allow an attacker to fully compromise all of the AWS-managed GitHub repositories inc...
Cross Site Scripting, usually called XSS, happens when a website shows user input without properly checking it first.In simple terms:the website trusts dat...
Companies today rely heavily on web applications for conducting their business. From online banking sites to ecommerce stores, web applications serve three...
Our blog insights are backed by hands-on service delivery. Whether you need a penetration test, vulnerability assessment, emergency website recovery, or secure web development — our UK cybersecurity specialists are ready to help.
Emergency malware removal, backdoor elimination, blacklist delisting, and full post-incident hardening for compromised websites.
Authorised simulated attacks exposing real vulnerabilities in your web applications, networks, and infrastructure before attackers do.
Systematic identification and prioritisation of security weaknesses across your digital estate — with actionable remediation guidance.
OWASP-aligned web application development with security engineered in from architecture through to penetration-tested deployment.
Advanced adversary simulation testing your organisation's detection and response capabilities against real-world threat actor behaviour.
Actionable intelligence on threat actors, attack vectors, and emerging risks targeting your sector — enabling proactive defensive decisions.
© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067