2023-01-13 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Several vulnerabilities were present in how Google Cloud Shell (ssh.cloud.google.com) handled OAuth credentials. These included an open-redirect vulnerability, where attackers could redirect users to malicious sites to capture their credentials, and a validation bypass that allowed tokens to be submitted to user-defined URIs, circumventing normal security checks. Additionally, Google Cloud Workstations did not correctly tie the state parameter to the session that generated it, which allowed val…
P0
2023-01-12 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in Vertex AI Workbench allowed attackers to take over victims' Google Cloud projects through client-side SSRF. The initial bug involved unauthorized access to authentication tokens, which was later fixed. A bypass was later discovered (and also fixed) using open redirects in Feedburner and CSRF token manipulation.
P0
2023-01-12 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Google Cloud Compute Engine (GCE) was vulnerable to SSH key injection by abusing an SSH-in-browser feature to change username and password. An attacker could send a specially-crafted link to a target user, and if the victim was logged into GCP and clicked the link, the attacker's SSH username and password would be added to the target machine, thereby allowing the attacker to log into it. This was possible because no random token or CSRF protection had been implemented for the abused feature. Fo…
P0
2023-01-11 07:17 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
New APT hitting Asia-Pacific, Europe that goes deeper and darker
P0
2023-01-10 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this blog, we'll explore our new Mac agent, what we look for and why—and where we’re heading.
P0
2023-01-06 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A CORS misconfiguration in Google Cloud's Identity-Aware Proxy (IAP) could have allowed attackers to disclose the email address of an authenticated user in websites protected by IAP, by convincing the user to connect to an attacker-controlled domain. This vulnerability enabled attackers to exploit CORS settings to access sensitive email information of both authenticated and unauthenticated users (with the latter requiring additional social engineering).
P0
2023-01-05 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this blog, we expose how hackers go after the most vulnerable and critical aspects of an endpoint and how managed EDR can help stop attacks in their tracks.
P0
2023-01-03 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Two of Huntress’ heavy hitters John Hammond and Dray Agha lace up their gloves to join the good fight and add their predictions for 2023.
P0
2022-12-29 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress' analysis of a new exploit chain (called OWASSRF) that can lead to critical remote code execution on unpatched Exchange hosts.
P15
2022-12-22 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Azure Cognitive Search (ACS) is a full-text search engine service. A new non-default feature allowed for a network control to bypassed, permitting an attacker to submit search queries to any other tenant's network-isolated ACS instance. However, abusing this required a valid API key to access the data plane of the target, along with a number of pieces of information about the target environment (such as the subscription ID and the name of the index to query).
P0
2022-12-21 13:38 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB discovers banking Trojan targeting users of more than 400 apps in 16 countries
P0
2022-12-20 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this blog, we’re going to focus on how Shodan helps us unveil some of the infrastructure that supports ransomware actors.
P15
2022-12-16 13:42 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
8 online scams to protect your customers from
P0
2022-12-15 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
In Azure Serverless Functions, a new container is generated by the host for every function, which is then terminated and deleted after several minutes. Palo Alto discovered that an API call was available to bind one path to another within the container (called "init_server_pkg_mount_BindMount") that could be called by a low-privileged user but executed with root privileges. This could enable a malicious tenant to escalate their privileges to root, and then escape their container by abusing the …
P0
2022-12-14 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Our team has been tracking conversations surrounding ConnectWise Control vulnerabilities and alleged exploitation. We politely disagree with the threat and criticality presented by the security researcher.
P0
2022-12-13 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in Elastic Container Registry (ECR) Public could have allowed a malicious actor to delete, update, or create ECR Public images, layers, or tags in registries and repositories belonging to any other AWS account, by abusing undocumented API calls. A malicious actor could have exploited this to delete any or all images in the Amazon ECR Public Gallery or update the content of any existing image to inject malicious code on any machine that would pull and run it.
P0
2022-12-13 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Our partners at Clear Guidance Partners experienced the value of our EDR capabilities in real-time, pitting them against an active ransomware attack.
P15
2022-12-06 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In the last blog of our defense evasion series, we'll cover granular advice for monitoring and detecting defense evasion.
P0
2022-12-01 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
IBM Cloud Databases for PostgreSQL was vulnerable to an attack sequence comprised of PostgreSQL privilege escalation via SQL Injection and chaining of three secrets scattered in the service environment (a K8s service account token, a private container registry password, and CI/CD server credentials), which were abusable due to overly permissive network access to internal build servers. A malicious actor could have exploited this vulnerability to remotely execute code in other customers’ environ…
P10
2022-11-29 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Incident response is a lot like a choose your own adventure exercise. We cover the ground rules and talk about some incidents we’ve helped partners with.
P0
2022-11-28 13:47 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
A money mule is someone who moves stolen funds across bank accounts on behalf of cybercriminals. Learn how money mules operate and how you can proactively counteract mule accounts.
P0
2022-11-22 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
We're seeing a rise in Qakbot activity. Here's what you need to know to keep your environments safe.
P0
2022-11-21 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
The AWS AppSync service could be coerced to assume arbitrary roles in other customers' accounts which trusted the AppSync service. This was due to insufficient validation of a serviceRoleArn parameter (caused by a case-sensitivity parsing issue). With this vulnerability, if an adversary knew the ARN of the role associated with AppSync in the target account, they could use it invoke arbitrary AWS API calls.
P0
2022-11-17 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
hack_it 2022 was jam-packed with hacker tradecraft, shady shenanigans, and—as always—a little spice. Check out our favorite moments and highlights!
P0
2022-11-15 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A strong security foundation is the cornerstone of any MSP’s success. Learn how to build this foundation—even if you're new to cybersecurity.
P0
2022-11-09 13:54 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB uncovers one thousand (and one) fake domains part of a scam campaign targeting users in KSA
P0
2022-11-08 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
With the beta release of the Huntress macOS agent, we wanted to share some of the Apple-y stuff we’ve been up to behind the scenes.
P15
2022-11-07 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Binary Security discovered and registered two dangling cloudapp.azure.com subdomains corresponding to subdomains at visualstudio.com. Had these been discovered and registered by an attacker, this would have been equivalent to a 1-click vulnerability for Azure DevOps: the attacker could have crafted a URL referring to the sign-in API for Azure DevOps Services (app.vssps.visualstudio.com) using one of the two subdomains in the "reply_to" field (since subdomains of visualstudio.com would be allowe…
P0
2022-11-03 13:30 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
En 2019, l'équipe Threat Intelligence de Group-IB a détecté une série d'attaques ciblant des organisations financières en Afrique.
P0
2022-11-03 11:26 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
The French-speaking gang managed to carry out over 30 successful attacks on banks, financial services and telecommunications companies, mainly located in Africa.
P0