Other
Other
An RCE in Google Cloud Deployment Manager could have allowed an attacker to make requests to internal Google services, authenticated as a privileged service account.
The success of enterprise ransomware attacks has motivated more and more threat actors to join the game.
NCSC technical paper about the privacy and security design of the NHS contact tracing app developed to help slow the spread of coronavirus.
Useful feature that can help forensic analysts and incident responders to reconstruct user activities.
GuardDuty detected CloudTrail being outright disabled, but did not detect if an attacker with the necessary permissions filtered out all events from CloudTrail via PutEventSelectors, resulting in defenders having no logs to review. AWS fixed this issue by adding a GuardDuty detection that triggers if PutEventSelectors is used to disable all event types.
Google Cloudshell leveraged websockets without validating that the origin matched the current instance host. An attacker could therefore host a CSWSH attack on a Cloudshell instance they own, disabling authentication via access to the underlying VM. They could then start the OAuth process with a spoofed host header, using phishing to get the target Cloud Shell user into following a redirection link, completing the OAuth process and ending in successful CSWSH, which would allow the attacker to h…
A vulnerability in Google's common JavaScript library allowed bypassing domain validation checks across multiple Google products. By using a backslash character in URLs, an attacker could make the regex parser and browser disagree on the authority (domain) portion of a URL, allowing injection of arbitrary domains that pass whitelisting checks.
Explore the forensic perspective of the Microsoft Edge Chromium-based version and its features, such as msedge_proxy, edge cache location, and more.
In a rare encounter, we found ourselves directly interacting with a cybercriminal that took us down a dark web rabbit hole.
A Vulnerability in App Service could allow an unprivileged function run by the user to execute code in the context of NT AUTHORITY\system, thereby escaping the sandbox. This vulnerability allowed cross-account access when using the Free/Shared tier.
A summary of the NCSC’s security analysis for the UK telecoms sector
Read more about Huntress validating the SolarWinds N-central “Dumpster Diver” Vulnerability.
An AWS employee pushed sensitive data to a public github bucket, including customer information and credentials. Note: This issue is outside the scope of this database's usual criteria for inclusion, but has been kept for historic reasons, as it was included in the original CSP Security Mistakes dataset.
The Huntress team validates eight vulnerabilities found in ConnectWise Control that ranged from low to high severity.
Forensic artifacts, which can be found during forensic examination of a Windows endpoint.
GCP's Speech-to-Text "operations/list" and "operations/get" APIs would return data that did not belong to the caller when no parameters were provided. It is unclear whether this was cross-customer data disclosure, or potentially test or internal data.
Cobalt Gang is alive and well, and continued to attack financial institutions around the globe in 2019.
An SSRF bug in GCP's Stackdriver Debugger feature's code import could have been used to leak the authentication token of the user to an attacker-controlled server. Exploitation would require that the user had previously configured a specific code hosting service (such as GitHub), and could be tricked into clicking a malicious link.
Wouter ter Maat discovered 9 vulnerabilities in GCP Cloudshell that could allow an attacker to access resources in another customer's environment.
GCP Cloudshell has been affected by various XSS and CSRF vulnerabilities stemming from different root causes related to authentication handling, markdown editing, file uploading and more. Explotiation of these vulnerabilities normally requires user interaction through social engineering (convincing a potential victim to click a malicious link).
Windows Prefetch files were introduced in Windows XP and since that time have helped digital forensics analysts and incident responders find evidence of execution.
A vulnerability was discovered in Google Cloud Platform's AI Hub service, allowing unrestricted file uploads. This could potentially lead to bypassing Same-Origin Policy by uploading SWF files, enabling CSRF attacks across browsers, and exploiting CVE-2014-8453 on IE with Adobe Reader installed. The issue resulted in a $1337 bounty reward.
The story about Group-IB searching for graph analysis solution and creating its own unique instrument
Learn how Huntress helped an MSP partner contain and remediate an Emotet/TrickBot infection with Assisted Remediation.
Group-IB specialists detected a new JS-sniffer family called FakeSecurity.
All about WhatsApp forensics and the wealth of data extracted from a device through forensic analysis.
Group-IB experts have detected a massive email campaign spreading similar ransom demands sent to banks and financial organizations across the word.