2021-02-15 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An attacker could gain root privileges on their Azure Cloud Shell container, escape from the container, and then gain root privileges on the underlying node, the root cause being an insecure kubelet port (10250), among other cluster misconfigurations. Once they could access the node filesystem, an attacker could extract kubelet API credentials which allowed listing all pods and nodes in the cluster, including those belonging to other tenants. Moreover, an attacker could bypass RBAC policies in …
P0
2021-02-09 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
To avoid detection, hackers often turn a system’s own tools against itself. Here, we examine a malicious payload that was executed using PowerShell.
P0
2021-01-26 09:13 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Forensic examination of incidents involving source code leaks
P0
2021-01-26 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Read about Huntress’ Managed Antivirus service and how it enables MSPs and IT admins to strengthen endpoint protection and rebalance their cyber stack.
P0
2021-01-20 12:00 UTC
Government
UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC
Technical report on best practice use of this fundamental data routing protocol.
P0
2021-01-19 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Microsoft Defender Antivirus is among one of the leading antivirus contenders. Here’s why it’s worth taking another look at Defender AV.
P0
2021-01-12 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn manual malware analysis techniques used by threat researchers. Explore static & dynamic analysis, reverse engineering tools, and real-world investigation methods.
P0
2020-12-30 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A bug in the GKE gVisor sandbox's network policy implementation allowed access to the Google Compute Engine metadata API.
P0
2020-12-29 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
At Huntress, beta means learning. Our goal is to accelerate and streamline security defense, which means releasing what we’re working on often.
P0
2020-12-23 09:19 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
As part of UltraRank's new campaign, Group-IB Threat Intelligence team discovered 12 eCommerce websites infected with their JavaScript-sniffer.
P0
2020-12-22 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
We take a look back at some of the more interesting — and innovative — hacker tradecraft we saw over the course of 2020.
P0
2020-12-20 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Information about this issue is under NDA, but AWS customers can read about it on pages 120-121 of the report, which is available for download through AWS Artifact. Note: This issue is outside the scope of this database's usual criteria for inclusion, but has been kept for historic reasons, as it was included in the original CSP Security Mistakes dataset.
P0
2020-12-17 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Annual security awareness training is a waste of time. We discuss why an ongoing security awareness program is required to protect against cyber threats.
P0
2020-12-14 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress covers the breaking news about Solarwinds’ Orion platform being exploited as part of a coordinated attack to distribute malware.
P0
2020-12-07 09:23 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
A story about operators of JS-sniffer FakeSecurity distributing Raccoon stealer
P0
2020-12-02 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
TrickBot has unleashed yet another module in its growing arsenal specifically targeting firmware vulnerabilities, named TrickBoot.
P0
2020-11-27 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress CEO Kyle Hanslovan has a lot to be thankful for in 2020 — and it starts with the MSP community.
P0
2020-11-24 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In this blog, we dissect a sample of malware that makes clever use of batch scripting obfuscation—turns out it was a launcher for TrickBot!
P0
2020-11-22 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
When the compute API is enabled on a GCP Project, the default compute account is created. This account gets the primitive role Editor assigned by default, which allows for a wide variety of privilege excalation and resource abuse in the project. Especially, all new VMs created inherit this permissions by default. This issue is arguably a technical decision by GCP, but the documents advise customers to undo this.
P0
2020-11-22 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Composer, Dataflow, Dataproc, Dataprep and Data Fusion all used the Compute Engine default service account by default and relied on product-level IAM permissions without requiring the iam.serviceAccount.actAs permission, meaning that users of these services could elevate their privileges. Following disclosure, GCP changed these services to require this permission.
P10
2020-11-20 13:34 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Analysis of TTPs employed by Egregor operators
P0
2020-11-18 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Even the best cybersecurity tools won’t configure and sell themselves. That's why we're thrilled to introduce a new Huntress service: Partner Enablement!
P0
2020-11-12 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An SSRF bug in Google Cloud Monitoring's uptime check feature could have been used to leak the authentication token of the service account used for these checks. The issue was resolved but later bypassed by Omar Espino (@omespino), requiring another fix.
P0
2020-11-01 13:38 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Top Russian companies and banks under attack from OldGremlin - a group controlling TinyCryptor ransomware
P15
2020-10-22 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A recap of hack_it 2020, a virtual security training event packed with interactive exercises, malware research and analysis, and more.
P0
2020-10-19 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An attacker with sufficient privileges in AWS to modify the route table and some other EC2 privileges, could pretend to be a metadata server and provide an attacker controlled bootup script to EC2s to move laterally.
P0
2020-10-17 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AI Hub Jupyter Notebook server lacked a check of the Origin header that led to a CSRF vulnerability. An attacker could have read sensitive data and execute arbitrary actions in customer environments.
P0
2020-10-17 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An attacker who gained access to IAM credentials could enumerate a subset of the privileges they had access to without logging to CloudTrail. This would allow them to perform the typically noisy permission enumeration process undetected.
P0
2020-10-15 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS have released or changed managed IAM policies in unexpected and insecure ways. Examples include: CheesepuffsServiceRolePolicy, AWSServiceRoleForThorInternalDevPolicy, AWSCodeArtifactReadOnlyAccess.json, AmazonCirrusGammaRoleForInstaller. The worst being the ReadOnlyAccess policy having almost all privileges removed and unexpected ones added.
P0
2020-10-10 13:41 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Keeping user digital identity safe
P0