Other
“We find many things that others do not even see”
Nikita Rostovtsev on current cyber threats and his profession
Nikita Rostovtsev on current cyber threats and his profession
Unsecured public-facing database allowed anyone to access ID selfies for months
Azure forces the install of an agent on Linux VMs, which contained a vulnerability that allowed privilege escalation (note that this vulnerability is different than OMIGOD, which also resided in the OMI agent).
This blog dives into triangulation as a guiding concept during investigations and reporting.
Tenable Research discovered a privilege escalation flaw that allows a user to escalate privileges to that of the root user within the context of a Spark VM. They also discovered a separate flaw that allows a user to poison the hosts file on all nodes in their Spark pool, which would allow an attacker to redirect subsets of traffic and snoop on services users generally do not have access to.
Group-IB identifies massive campaign capable of targeting clients of major Vietnamese banks
Executing Cloud Functions or Cloud Run in any project and in any organization allowed bypassing the GKE Authorized Networks (aka Kubernetes control plane firewalls) of a cluster in a different project or organization.
If you follow the NIST cybersecurity framework, you'll ensure that your money is spent on the right areas to build an effective defense strategy.
APT SideWinder’s new tool that narrows their reach to Pakistan
Two API calls used by Amazon Managed Workflows for Apache Airflow (MWAA) to convert AWS IAM credentials into tokens that can be used to login to Airflow (CreateCliToken and CreateWebLoginToken) were logging the tokens to Cloudtrail. The event included the hostname for the airflow server, so everything required to login to Airflow was in the event. However, the issue was largely mitigated by the fact that the tokens are only valid for 60 seconds and CloudTrail delivers logs on average about ever…
It can be difficult to demonstrate the value of cybersecurity when your stack is doing its job. Here is how you can show the hidden value of cybersecurity.
A new attack vector enables hackers to more easily compromise users with malicious Microsoft Office documents.
Continuing our blog series on defense evasion, this blog dives into some practical, real-world examples of defense evasion in action.
While testing rate-limiter protection, The researcher noticed that when forcing HTTP/1 requests and injecting a space after `X-Forwarded-For` he was able to override this specific header, letting him impersonate any IP. Any internal header could have beem overridden, also the one that should not be exposed/forwarded by the client, such as `CloudFront-Viewer-Country-Region` or any other `CloudFront` enhanced header. This special security issue was affecting all AWS users with that a specific set…
Learn how The Huntress Managed Security Platform is built to equip SMBs with the ability to swiftly and accurately mitigate threats.
Read about our latest addition, API, and how it enables MSPs and IT administrators to monitor, manage and maintain their cybersecurity stack how they want.
Assessing the cyber security threat to UK organisations using Enterprise Connected Devices.
Key findings from the 5th year of the Active Cyber Defence (ACD) programme.
This blog shows how to catch an adversary moving from machine to machine, how to terminate this movement and how to evict the adversary from your network.
Azure Synapse Analytics and Azure Data Factory were vulnerable to cross-tenant access and code execution. This was made possible via a combination of (1) a shell injection RCE vulnerability in the integration runtime, (2) credentials for multiple customers stored on a shared host and (3) an insecure management server API.
We recap some of the lessons we have learned over the past year thanks to the Colonial Pipeline attack.
This report outlines the risks associated with the use of official and third party app stores.
An introduction to defense evasion as an attack tactic. Read on to explore what defense evasion is and why it’s important to understand how it’s used.
Two malicious versions were created of packages previously used by AWS. The packages were officially authored and maintained by AWS before they were removed by their legitimate author, and once the packages were removed, their names became available and the two packages were then populated with malicious code. If AWS-deployed software had any dependencies on these packages, this would have led to a dependency confusion attack.
A chain of critical vulnerabilities was discovered in Azure Database for PostgreSQL Flexible Server, allowing unauthorized read access to other customers’ PostgreSQL databases, thus bypassing tenant isolation. If exploited, a malicious actor could have replicated and gained read access to Azure PostgreSQL Flexible Server customer databases.
Sometimes hackers can be overly confident in their malware. Take a journey with us through a malware sample that contains no obfuscation whatsoever.
A technical analysis of a new variant of the SparrowDoor malware.
The Amazon SSM Agent (used for managing EC2 instances via Amazon Systems Manager) created a world-writable sudoers file, which would have allowed local attackers to inject Sudo rules and escalate privileges to root. This could occur in certain situations involving a race condition.
AWS's hotpatches for Log4shell worked as intended but introduced new container escape vulnerabilities.
Russian-speaking ransomware gang OldGremlin resumes attacks in Russia