Security Journalism
Legitimate Apps as Traitorware for Persistent Microsoft | Huntress
Dive into how Huntress caught a threat actor adding several legitimate email apps to maintain persistent access to a compromised Microsoft 365 environment.
Dive into how Huntress caught a threat actor adding several legitimate email apps to maintain persistent access to a compromised Microsoft 365 environment.
Discover the key phases of the threat hunting process and how threat hunters structure their hunts to proactively seek out threats.
Is it worth switching to Microsoft Defender Antivirus? Spoiler alert: We think yes! Explore why Defender is a solid AV solution.
Explore how Huntress stopped a massive business email compromise (BEC) attack targeting multiple user accounts within a single organization.
This blog post provides a comprehensive overview of the importance, benefits and challenges of cyber insurance that every MSP should be aware of.
Dive into the improvements and progress we’ve made with Huntress Security Awareness Training since acquiring Curricula one year ago.
An information disclosure vulnerability in the Google Cloud Build service could have allowed an attacker to view sensitive logs if they had gained prior access to a GCP environment and had permission to create a new Cloud Build instance (cloudbuild.builds.create) or permission to directly impersonate the Cloud Build default service account (which is highly privileged by design and therefore considered to be a known privilege escalation vector in GCP). An attacker could then potentially use this…
In this blog, explore how Huntress caught an attempt at financial fraud through business email compromise (BEC) in Microsoft 365.
Discover how organizations unwittingly create vulnerabilities by misconfiguring their cloud infrastructure
In this blog, we explore the long-term impact of the MOVEit exploitation and how defenders can stay vigilant and learn from the past.
Key findings and full report from the 6th year of the Active Cyber Defence (ACD) programme.
Can we use anomalous user agents to detect potential business email compromise (BEC) in Microsoft 365? Explore what we found through threat hunting for BEC.
Do you need third-party security for macOS? Discover if Apple’s malware prevention products, XProtect and XProtect Remediator, are good enough solutions to keep users safe.
A client-side desync vulnerability was discovered in Front Door, one of Azure's CDN solutions, caused by mishandling of the 'Content-Length' header in HTTP requests. Exploiting this vulnerability would most likely require user interaction through social engineering (such as clicking on a malicious link), but could allow an attacker to steal session cookies or forge responses to victim requests.
Discover how Huntress Managed Identity Threat Detection and Response identified three business email compromise (BEC) attacks within 72 hours of each other.
An updated report from the NCSC explaining how UK law firms - of all sizes - can protect themselves from common cyber threats.
A critical authentication bypass vulnerability was discovered in Google Cloud API Gateway, affecting its JWT authentication method. The flaw, stemming from a business logic bug in the ESPv2 service proxy, allowed attackers to bypass authentication controls by manipulating HTTP methods. This vulnerability impacted various authentication methods including Firebase, Auth0, Okta, and Google ID tokens.
Descope identified a possible misconfiguration in Azure AD which could lead to misuse of the "Log in with Microsoft" authentication method on a web app. If an application relies on email attribute claims for authentication (which is against best practice) and also merges user accounts without proper validation, an attacker could falsify an email claim to gain full control over the target account. Descope and Microsoft Microsoft identified several popular multi-tenant applications with users tha…
Need help approaching the security sales conversation? Use these tips to walk into your next client meeting armed with points for selling cybersecurity.
Get all the undisclosed details that our investigators uncovered on CryptosLabs' full scope of fraudulent schemes
Orca discovered vulnerabilities in Azure Bastion and Azure Container Registry that could have enabled an attacker to achieve Cross-Site Scripting (XSS) by using iframe postMessages. The vulnerabilities allowed embedding of endpoints within remote attacker-controlled servers using the iframe tag, thereby granting unauthorized access to the victim’s session in the affected service if they were tricked into navigating to an attacker-controlled website. The root cause was that certain web pages in …
A bucket traversal vulnerability was discovered in the google.cloud.storage.transfer_manager.upload_chunks_concurrently() function of Google Cloud Storage. This issue could potentially allow unauthorized access to files in different buckets or directories within the same project.
Everything you need to know about Microsoft's authentication control, Granular Delegated Admin Privileges (GDAP).
Binary Security found two vulnerabilities in the legacy Azure Resource Manager (ARM) REST API. The first vulnerability allowed an attacker with Reader access to an Azure Function, acting from a Windows host, to get an admin token that could be exchanged for a master key granting access to all operations in Kudu (the Functions deployment service). This would allow them to tamper with the function by deploying malicious code to it. The other vulnerability allowed an attacker with Reader access to…
Explore the recent disclosures concerning Volt Typhoon, a threat actor engaged in the widespread exploitation of external-facing services and network appliances.
AWS Directory Service didn't check the iam:PassRole permissions when using the EnableRoleAccess action. This could have been used for privilege escalation by an authenticated user with sufficient permissions (ds:EnableRoleAccess), if the role had a trust policy that allowed use by Directory Service.
This blog illustrates how the Splunk Universal Forwarder (UF) can be used as traitorware for persistence and remote code execution.
What we know about APT campaign to date and how to detect it
A vulnerability was discovered in Cloud SQL for SQL Server that allowed customer administrator accounts to create triggers in the tempdb database and use those to gain sysadmin privileges in the instance. The sysadmin privileges would give the attacker access to system databases and partial access to the machine running that SQL Server instance.
Our team is tracking in-the-wild exploitation of a zero-day vulnerability against Progress' MOVEit Transfer web application that allows for escalated privileges and unauthorized access.