2022-04-20 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
The Amazon SSM Agent (used for managing EC2 instances via Amazon Systems Manager) created a world-writable sudoers file, which would have allowed local attackers to inject Sudo rules and escalate privileges to root. This could occur in certain situations involving a race condition.
P10
2022-04-19 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS's hotpatches for Log4shell worked as intended but introduced new container escape vulnerabilities.
P10
2022-04-14 11:36 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Russian-speaking ransomware gang OldGremlin resumes attacks in Russia
P15
2022-04-14 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A comprehensive guide to the NIST cybersecurity framework, its five main functions and how you can use the NIST framework to improve your cybersecurity posture.
P0
2022-04-12 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
The AWS VPN Client application is affected by an arbitrary file write as SYSTEM, which can lead to privilege escalation and an information disclosure vulnerability that allows the user's Net-NTLMv2 hash to be leaked via a UNC path in a VPN configuration file.
P10
2022-04-12 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn why Huntress is built to complement—not complicate—our partners’ daily operations and deliver on our mission to secure the 99%.
P0
2022-04-11 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability was discovered in the Aurora PostgreSQL log_fdw extension for Amazon Relational Database Service (RDS), allowing an attacker to read files on the EC2 host and obtain credentials for an internal AWS service.
P0
2022-04-08 15:57 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Fake giveaways hit bitcoiners again. Now on YouTube
P0
2022-04-05 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Undocumented Azure AD APIs could allow access to internal information of any organization that uses Azure AD. Collected details included licensing information, mailbox information, and directory synchronization status.
P0
2022-04-05 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
We explore the third arm of our ThreatOps team—Support—and dive into how the team operates.
P0
2022-03-31 12:05 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
What we know about Spring4Shell so far
P0
2022-03-31 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
This year for World Backup Day, we’ve asked our friends and backup/disaster recovery experts at Servosity to share their best “backup” tips.
P0
2022-03-29 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Take a behind-the-scenes look at what our security researchers do in this Q&A session.
P0
2022-03-28 13:33 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB unveils three groups of fraudsters behind delivery scams in Singapore
P0
2022-03-22 12:00 UTC
Government
UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC
Assessing the security of network equipment.
P0
2022-03-22 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
There was a misconfiguration with Simultaneous Multi-Threading (SMT), also known as Hyper-threading, in GKE Sandbox images, causing nodes to be potentially exposed to side channel attacks such as Microarchitectural Data Sampling (MDS).
P0
2022-03-22 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Hop behind the proverbial shoulders of one of our ThreatOps analysts and vicariously experience a day in his life.
P0
2022-03-15 13:56 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Intelligence-Driven Attack Surface Management
P0
2022-03-15 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
What is endpoint detection and response (EDR) and why is it important? Dive into what EDR is, its history and what to look for in EDR solutions today.
P0
2022-03-14 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how to break the silence in cybersecurity culture and promote open communication to enhance your organization's security posture.
P0
2022-03-10 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
The AWS RDS service does not enable secure transport layer security by default, allowing clients to connect insecurely. Additionally, for the more commonly used MySQL and MariaDB RDS engine types, this setting cannot be enabled at all.
P0
2022-03-09 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Azure Logic Apps use API Connections to authenticate actions to services. Having Contributor access to an Azure Resource Manager (ARM) API Connection would allow someone to create arbitrary role assignments as the connected user. This was supposed to be limited to actions at the Resource Group level, but an attacker could escape to the Subscription or Root level with a path traversal payload. The root cause of this behavior was that such a payload would meet the Swagger API definition, and it w…
P10
2022-03-08 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Unit 42 researchers disclosed several vulnerabilities and attack techniques in GKE Autopilot to Google, the root cause being insufficient verification of allowlisted workload image names. An attacker with permissions to create a pod could have abused these vulnerabilities to (1) escape their pod and compromise the underlying node, (2) escalate privileges and become full cluster administrators, and (3) covertly persist administrative access through backdoors that are completely invisible to clus…
P0
2022-03-08 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this blog, we get candid about our view of today’s security space. Plus, we share all the details on how and why we build security products the Huntress way.
P0
2022-03-07 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An exposed endpoint in the Azure Automation Service allowed to steal Azure API credentials from other customers
P0
2022-03-01 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
We discovered malicious, targeted advanced persistent threat (APT) activity on a partner's system. Here, we dive into the BABYSHARK malware strain.
P0
2022-02-24 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Cloud Armor has a documented limitation of 8 KB as the maximum size of web request that it will inspect. The default behavior of Cloud Armor in this case can allow oversized malicious requests to bypass Cloud Armor and directly reach an underlying application. Moreover, Cloud Armor does not warn users of this limitation during policy creation or when configuring rules from within the web UI, and can only find a reference to the 8 KB limit in the [Cloud Armor documentation](https://cloud.google.…
P0
2022-02-18 11:59 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
With ransomware attacks on the rise, companies need to take a proactive approach to security. Group-IB has put together a list of actionable tips to help you protect your organization from the ransomware threats in 2022.
P15
2022-02-16 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Hackers could be outsmarting preventive tools by making trivial changes to default settings. We dive into our research in this blog.
P0
2022-02-15 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Opsmorph discovered an improper access control vulnerability in authorization logic common in applications built on AWS. The vulnerability means a user with permission to create a new Cognito User Group could fool authorization checks into thinking that the user is in any other existing Cognito User Group in the same User Pool, referred to as user group spoofing. When API Gateway is secured with a Cognito User Pool Authorizer it concatenates group names from the identity token into a comma sepa…
P0