Other
Curse of the Krasue: New Linux Remote Access Trojan targets Thailand
This piece of malware has an insatiable appetite. Group-IB's Threat Intelligence unit offers their insights on the new RAT used in attacks against Thai companies.
This piece of malware has an insatiable appetite. Group-IB's Threat Intelligence unit offers their insights on the new RAT used in attacks against Thai companies.
Discover how leveraging technical indicators can boost cybersecurity effectiveness and empower small business defense. Read on for practical insights.
An update on our MDR for Microsoft 365 product, some recent improvements, and what fixes and features are coming soon.
Learn more about how Huntress' Managed Security Awareness Program can help your employees follow CIS control requirements.
Unit 42 researchers discovered a security risk in Google Workspace's domain-wide delegation feature that allows a GCP identity with necessary permissions to generate access tokens to impersonate Google Workspace users and access their data. This mismatch between GCP permissions and Google Workspace access could be exploited by malicious insiders or attackers with stolen credentials.
A look inside the evolving landscape of macOS malware. Dive into the current state of macOS threats and learn from a glossary of essential macOS terms.
Dive into our analysis of the CVE-2023-43117 threat in CrushFTP and the growing popularity of MFT application exploitation as a tactic for adversaries.
Threat actors frequently make use of native utilities during incidents. However, this blog post discusses a rarely-observed means of data exfiltration.
Actionable guide to hunting for the Windows Services abuse by using Group-IB MXDR.
Navigate the SMB threat landscape with Huntress’ SMB Threat Report. Gain insights into evolving cyber threats targeting SMBs. Read on for key insights.
A vulnerability in Azure Function Apps allowed extraction of Managed Identity credentials from the encrypted startup context of Linux containers. This gave attackers with container access the ability to persist as the Managed Identity, breaking the intended security model. Microsoft has since patched the issue by encrypting the sensitive payload.
Azure CLI commands were found to leak sensitive information, including credentials, through GitHub Actions logs. The vulnerability affects multiple Azure CLI commands and could expose secrets in public and private repositories. Microsoft has issued updates to Azure CLI, Azure Pipelines, and GitHub Actions to address the issue.
Palo Alto discovered that Azure CLI commands were found to leak sensitive credentials and environment variables in GitHub Actions logs. This issue affects both public and private repositories, potentially exposing secrets to unauthorized parties. The problem stems from the Azure CLI's design to echo back accessed/created/updated/deleted resource information, which can include sensitive data. Later research by Orca Security revealed that AWS CLI and Google Cloud CLI were affected by the same iss…
Huntress has analyzed the emerging SysAid CVE-2023-47246 vulnerability and recreated the attack chain with a proof-of-concept exploit.
Huntress has uncovered a series of unauthorized access, revealing a threat actor using ScreenConnect to infiltrate multiple healthcare organizations.
Take a deep dive into the operations of one of the most active players in the Ransomware-as-a-Service market.
SafeBreach Labs researchers developed methods to leverage Microsoft Azure's Automation Service for free, undetectable cryptocurrency mining. They found three ways to execute miners: two using their own environment and Azure's resources for free, and one in a victim's environment undetected. The techniques could potentially be used for any task requiring code execution on Azure.
CVE-2023-22518 is being exploited in Confluence for Cerber ransomware deployment. Read up on Huntress’ observations and mitigation guidance.
AppFlow had an undocumented service called sandstoneconfigurationservicelambda. An undocumented field (awsOwnedManagedAppCredentialsArn) could be used during connector registration and connector updates. Specifying a victim's Secret ARN as that field disclosed the clientId and clientSecret, so long as the victim Secret ARN belonged to a connection profile which is of the type OAuth or contains clientId and clientSecret.
The AppFlow WooCommerce connector allowed specification of a full URL. The connector included details of response content when the URL offered an unexpected response. This means you could make arbitrary GET requests to any URL from the WooCommerce connector, and view the response content. The response in the error was truncated to 500 characters.
A vulnerability in Google Bard allowed for prompt injection and data exfiltration through its Extensions feature. By injecting malicious instructions into shared Google Docs, an attacker could force Bard to render images with exfiltrated chat history data in the URL. The exploit bypassed Content Security Policy using Google Apps Script.
Amazon Managed Workflows for Apache Airflow (MWAA) and the Task instance details page in the Google Composer UI were not patched against CVE-2023-29247 (Stored XSS). This meant that post-authentication, a threat actor could have exploited this to store their JavaScript payload in the victim's managed Apache Airflow instance and run JavaScript on behalf of the victim (who could be an admin or another user with higher permissions than the threat actor, thereby leading to privilege escalation). Wi…
CVE-2023-46604 is a critical remote code execution vulnerability in Apache ActiveMQ. Patch now to avoid any potential adversary exploitation.
This blog post is a retrospective on the Huntress team's month-long Capture the Flag (CTF) event, highlighting diverse challenges and hacker camaraderie.
Discover the alarming prevalence of exposed passwords on endpoints and how to safeguard your credentials. Learn from Huntress' findings and insights.
Get a close look at details of the most notable cases faced by Group-IB’s Digital Forensics and Incident Response (DFIR) team
\[Mise à jour du 22 novembre 2023\] L'éditeur a publié un document \[3\] le 20 novembre 2023 listant les différents journaux à analyser ainsi que les éléments à rechercher pour identifier une activité pouvant être liée à une compromission. Par ailleurs, la CISA a publié un avis de sécurité le 21...
In Azure AI Playground, a Prompt Injection attack could cause an LLM to return markdown tags. This would have allowed an adversary whose data makes it into the chat context (e.g., via an uploaded file) to achieve exfiltration of the victim’s data by rendering hyperlinks. However, the severity of this issue is low, as there were no integrations that could pull remote content. This means Indirect Prompt Injection was not possible, and it would require the victim to copy the malicious prompt from …
In Vertex AI Studio, a Prompt Injection attack could cause the LLM to return markdown tags. This could have allowed an adversary whose data makes it into the chat context (e.g., via an uploaded file) to achieve exfiltration of the victim’s data by rendering hyperlinks. However, the severity of this issue is low, as there were no integrations that could pull remote content. This means Indirect Prompt Injection was not possible, and it would require the victim to copy the malicious prompt from el…
Explore the art of phishing, learn how to spot common phishing scams and red flags, and understand the importance of security awareness training.