2020-10-06 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Amazon Elastic Kubernetes Service (EKS) uses IAM to provide authentication to the cluster through the AWS IAM Authenticator for Kubernetes (aws-iam-authenticator). Multiple issues were identified in the authenticator that could have allowed exploitation, namely (1) a lax regular expression used to verify presigned URLs; (2) HTTP client redirect follow (due to using Golang HTTP client in its default configuration); (3) use of the Golang URL.Query function (which silently drops parameters that Go…
P0
2020-10-01 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
A vulnerability in Google Cloud Shell allowed escalation from XSS to full instance takeover as root. The attack exploited an XSS in the markdown preview functionality to read sensitive files, obtain the instance's private key and hostname, and gain SSH access as root. The issue affected the Eclipse Theia-based editor used in Cloud Shell.
P15
2020-09-28 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
AWS KMS and all versions of AWS Encryption SDKs prior to version 2.0.0 were susceptible to information leakage (an attacker could create ciphertexts that would leak the user’s AWS account ID, encryption context, user agent, and IP address upon decryption), ciphertext forgery (an attacker could create ciphertexts that were accepted by other users) and lack of robustness (an attacker could create ciphertexts that decrypt to different plaintexts for different users).
P0
2020-09-28 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Lack of the privilege s3:PutBucketTagging did not restrict the ability to tag S3 buckets.
P0
2020-09-25 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An audit of an AWS open-source project identified a great deal of issues, and as a result AWS made the decision to take it down.
P0
2020-09-22 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
CloudFormation allows the use of Lambda-backed resource providers, wherein Lambda can be used to write custom provisioning logic to be executed during CloudFormation stack operations. The aforementioned Lambda functions were executed in an AWS-managed account (thus effectively allowing arbitrary code execution in that account), and were passed a set of credentials ("platformCredentials") for a role in this account that had several EventBridge permissions. These were sufficient for an attacker t…
P0
2020-09-17 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Hackers getting better at their tradecraft and their skills are becoming more and more accessible to other bad actors via the Dark Web.
P0
2020-09-15 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
The immutability of Lambda versions could be violated via a timing attack against CloudWatch Synthetics canaries.
P0
2020-09-10 13:46 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Dive in Recent ProLock's Big Game Hunting
P0
2020-09-01 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An attacker with the ability to create CloudFormation stacks could cause a denial-of-service on some CloudFormation actions within a single AWS account.
P0
2020-08-26 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
It was possible to list IAM service accounts of any GCP project, given only its ID, by forging a pageToken for the projects.serviceAccounts.list method of the IAM API. Due to the design of certain services in GCP, this issue could lead to exposure of sensitive information related to a project, and could be further used to enumerate unsecured resources in the platform, such as App Engine apps, Container Registry repositories, etc.
P0
2020-08-20 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
As a follow-up to our previous post, we recently uncovered a really peculiar piece of malware that works through a lot of different layers of abstraction.
P0
2020-08-18 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Researchers discovered vulnerabilities in Google Cloud SQL that allowed gaining unauthorized shell access to MySQL instances. By chaining SQL injection, parameter injection in mysqldump, and network spoofing, they were able to escape a Docker container and gain full access to the host VM running Cloud SQL.
P0
2020-08-18 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Three vulnerabilities in Google Cloud Shell were discovered, allowing attackers to execute arbitrary code and potentially steal user credentials. The bugs affected Ruby gemspec parsing, TypeScript plugin loading, and Go binary path manipulation in Cloud Run. These issues arose from mismatches between Cloud Shell's threat model and the assumptions of its underlying open-source components.
P0
2020-08-10 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
No summary available
P0
2020-07-28 12:00 UTC
Government
UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC
Joint report between the NCSC and KPMG UK is the first in a series to benchmark and track levels of diversity and inclusion in the cyber security industry.
P0
2020-07-27 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Using CloudTrail S3 data events, it was possible to determine the AWS account ID of any existing S3 bucket by calling any S3 API, getting denied, and looking at the value in the resource key in error message that showed up in CloudTrail.
P0
2020-07-23 12:00 UTC
Government
UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC
The NCSC report highlights the cyber threats faced by the sports sector and suggests how to stop or lessen their impact on organisations.
P0
2020-07-21 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Read about the value of Huntress' External Recon service, which highlights open ports and services that are exposed to the Internet.
P0
2020-07-14 12:00 UTC
Government
UK NCSC Threat Reports · indexed 2026-08-15 18:50 UTC
A summary of the NCSC’s analysis of the May 2020 US sanction which caused the NCSC to modify the scope of its security mitigation strategy for Huawei.
P0
2020-07-05 13:51 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Top 11 books on digital forensics, incident response, and malware analysis
P0
2020-07-01 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
Display of EC2 tags had XSS
P0
2020-06-24 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Read about the value of Huntress' Ransomware Canaries service, a mechanism to deliver faster detection of a ransomware incident.
P15
2020-06-22 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
At Huntress, our goal is not only to chase after changing threats but to remove obstacles that get in the way of new security innovation.
P0
2020-06-18 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
There’s no end to the stealthy ways in which attackers develop and execute their tradecraft. In this case, it's as simple as hiding in plain sight.
P0
2020-06-15 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An attacker with access to a hostNetwork=true container with CAP_NET_RAW capability can listen to all the traffic going through the host and inject arbitrary traffic, allowing to tamper with most unencrypted traffic (HTTP, DNS, DHCP, ...), and disrupt encrypted traffic. In GKE the host queries the metadata service at http://169[.]254.169.254 to get information, including the authorized SSH keys. By manipulating the metadata service responses and injecting our own SSH key, it is possible to gain…
P10
2020-06-12 00:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
How do we calculate the total impact of a data breach? Visit the Huntress Blog to learn more about how cyber security awareness training can help to mitigate risk.
P0
2020-05-29 13:54 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
When ice burns through bank accounts
P0
2020-05-21 00:00 UTC
Other
Cloud Vuln DB · indexed 2026-09-07 17:30 UTC
An RCE in Google Cloud Deployment Manager could have allowed an attacker to make requests to internal Google services, authenticated as a privileged service account.
P15
2020-05-14 14:09 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
The success of enterprise ransomware attacks has motivated more and more threat actors to join the game.
P15