Security Journalism
Not All Managed Is Created Equally | Huntress
A lot of companies use the word managed, leading to the idea that all solutions are the same when it comes to being managed; however, similar doesn’t mean the same.
A lot of companies use the word managed, leading to the idea that all solutions are the same when it comes to being managed; however, similar doesn’t mean the same.
Which cybercrimes will dominate the threat landscape for 2023 and beyond? Find out!
On 02 February 2023, an alert triggered in a Huntress-protected environment. We dive into triaging the threat in this blog.
AWS applies a rate limit to authentication requests made to the AWS Console in an effort to prevent brute-force and credential stuffing attacks. However, a weakness was discovered in the AWS Console authentication flow that allowed a partial bypass of this rate limit by pausing for 5 seconds every 30 attempts. This would enable an attacker to continuously attempt more than 280 passwords per minute (4.6 per second) against IAM users, which could have resulted in account compromise of users witho…
Helping analysts develop a better understanding of the elastic search syntax.
Multiple Azure Web services use a source control management (SCM) panel powered by Kudu and enabled by default. These services were all susceptible to a CSRF vulnerability due to an overly-permissive regular expression (regex) in a filter for malformed origins. This allowed origin bypass when using a domain name structured as 'victim.scm.azurewebsites.net._.attacker.com' (note the use of '._.', which looks like an emoji). Thus, if a target Azure user were tricked into visiting a specially craft…
In this blog, we’ll go on a short journey of how we dissected a vague Managed Antivirus alert and offer some ideas and methods for security analysts.
A vulnerability in Azure Active Directory allowed users to retain access to SAML applications after their assignment was removed. Attackers could exploit this to establish persistence and elevate privileges on targeted SAML applications. The flaw was triggered by chaining sign-in with additional application and specific parameters in the token request, bypassing user assignment verification.
Through an undocumented API service called 'iamadmin', attackers could invoke any of 13 read-only IAM actions without the activity being being logged to CloudTrail. These actions included listing group policies (iam:ListGroupPolicies), listing access keys (iam:ListAccessKeys), retrieving information about a role (iam:GetRole), and more. This could have enabled adversaries to perform enumeration and reconnaissance activity undetected after gaining a foothold in a victim AWS environment.
SSRF vulnerabilities were discovered in four Azure services: unauthenticated SSRF in Azure Digital Twins Explorer and Azure Functions, and authenticated SSRF in Azure API Management Service and Azure Machine Learning Service. All four vulnerabilities were full (non-blind) SSRF. The impact of these vulnerabilities was limited: while they would have allowed an adversary to scan local ports and find new services, endpoints, and files; they would not have allowed them to access metadata, connect to…
Having backups is only one component of a solid business continuity and disaster recovery plan.
This vulnerability chain exploits a Cross-Site Scripting (XSS) flaw (CVE-2021-41038) within the Theia IDE used in Google Vertex AI Workbench. An attacker could inject malicious JavaScript code into the Theia IDE. This code could then be used to steal the OAuth token associated with the project's default Compute Engine service account, because when a user-managed Vertex AI Workbench instance is created, it utilizes the project's default Compute Engine service account. At the time, this default s…
Several vulnerabilities were present in how Google Cloud Shell (ssh.cloud.google.com) handled OAuth credentials. These included an open-redirect vulnerability, where attackers could redirect users to malicious sites to capture their credentials, and a validation bypass that allowed tokens to be submitted to user-defined URIs, circumventing normal security checks. Additionally, Google Cloud Workstations did not correctly tie the state parameter to the session that generated it, which allowed val…
A vulnerability in Vertex AI Workbench allowed attackers to take over victims' Google Cloud projects through client-side SSRF. The initial bug involved unauthorized access to authentication tokens, which was later fixed. A bypass was later discovered (and also fixed) using open redirects in Feedburner and CSRF token manipulation.
Google Cloud Compute Engine (GCE) was vulnerable to SSH key injection by abusing an SSH-in-browser feature to change username and password. An attacker could send a specially-crafted link to a target user, and if the victim was logged into GCP and clicked the link, the attacker's SSH username and password would be added to the target machine, thereby allowing the attacker to log into it. This was possible because no random token or CSRF protection had been implemented for the abused feature. Fo…
In this blog, we'll explore our new Mac agent, what we look for and why—and where we’re heading.
A CORS misconfiguration in Google Cloud's Identity-Aware Proxy (IAP) could have allowed attackers to disclose the email address of an authenticated user in websites protected by IAP, by convincing the user to connect to an attacker-controlled domain. This vulnerability enabled attackers to exploit CORS settings to access sensitive email information of both authenticated and unauthenticated users (with the latter requiring additional social engineering).
In this blog, we expose how hackers go after the most vulnerable and critical aspects of an endpoint and how managed EDR can help stop attacks in their tracks.
Two of Huntress’ heavy hitters John Hammond and Dray Agha lace up their gloves to join the good fight and add their predictions for 2023.
Huntress' analysis of a new exploit chain (called OWASSRF) that can lead to critical remote code execution on unpatched Exchange hosts.
Azure Cognitive Search (ACS) is a full-text search engine service. A new non-default feature allowed for a network control to bypassed, permitting an attacker to submit search queries to any other tenant's network-isolated ACS instance. However, abusing this required a valid API key to access the data plane of the target, along with a number of pieces of information about the target environment (such as the subscription ID and the name of the index to query).
Group-IB discovers banking Trojan targeting users of more than 400 apps in 16 countries
In this blog, we’re going to focus on how Shodan helps us unveil some of the infrastructure that supports ransomware actors.
8 online scams to protect your customers from
In Azure Serverless Functions, a new container is generated by the host for every function, which is then terminated and deleted after several minutes. Palo Alto discovered that an API call was available to bind one path to another within the container (called "init_server_pkg_mount_BindMount") that could be called by a low-privileged user but executed with root privileges. This could enable a malicious tenant to escalate their privileges to root, and then escape their container by abusing the …
Our team has been tracking conversations surrounding ConnectWise Control vulnerabilities and alleged exploitation. We politely disagree with the threat and criticality presented by the security researcher.
A vulnerability in Elastic Container Registry (ECR) Public could have allowed a malicious actor to delete, update, or create ECR Public images, layers, or tags in registries and repositories belonging to any other AWS account, by abusing undocumented API calls. A malicious actor could have exploited this to delete any or all images in the Amazon ECR Public Gallery or update the content of any existing image to inject malicious code on any machine that would pull and run it.
Our partners at Clear Guidance Partners experienced the value of our EDR capabilities in real-time, pitting them against an active ransomware attack.