[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Okta Confirms 2.5% of Customers Impacted by Lapsus Breach
Microsoft also admits it was hit by ransom group
> Background Check Company Sued Over Data Breach
Four parallel lawsuits filed against Creative Services Inc over alleged data security failings
> Anonymous Blob Access
Finding and accessing files stored in Azure Storage Accounts without authentication.
> Texan Accused of Credit Repair Scam
Defendant allegedly used websites and telemarketing to falsely claim that he could raise consumers’ credit scores
> White House: Russia Preparing Cyber-Attacks on US
US President warns malicious cyber activity is "part of Russia’s playbook"
> Flipper Zero - Initial Thoughts
After a bit of a delay my Flipper Zero finally arrived in the mail. If you are not familiar with Flipper Zero at all, check out the original Kickstarter page from a few years back. This is what the package looks like after opening. It contains the device, a USB cable, a quick start manual (mostly po...
> Security Teams are Responsible for Over 165k Assets
Concerns that the attack surface is expanding faster than ability to secure it
> #IMOS22: Ciaran Martin Discusses Cyber-Threats from the Russia-Ukraine Conflict
Ciaran Martin believes organizations must be prepared for heightened cyber risks emanating from the Russia-Ukraine conflict
> CVE-2022-27226: CSRF to RCE in iRZ Mobile Routers through 2022-03-16
Credits Vulnerability Discovery John Chris Mack Exploit Development Stephen Chavez Robert Willis Identification Default credentials were discovered on an iRZ Mobile Router login page. Utilizing root:root gave us access to the administrative functionality for the device. Having administrative access...
> Dark Web Drug Peddler Gets Nine Years
Police cracked encrypted chat messages to bust organized crime group
> Okta Investigates Possible Lapsus Breach
Concerns rise that ransomware group used access to target customers
> Soft Deleted Blobs
Recovering and accessing files in private Storage Accounts that have been deleted.
> New Mexico Appoints Cybersecurity Advisor
Annie Winterfield Manriquez becomes state’s first senior advisor for Cybersecurity and Critical Infrastructure
> FTC Accuses CafePress of Data Breach "Cover-Up"
Commission orders e-commerce platform to compensate small businesses and improve security
> AWS API Call Hijacking via ACM-PCA
By modifying the route53 entries and utilizing the acm-pca private CA one can hijack the calls to AWS API inside the AWS VPC
> Dental Care Data Breach May Impact 1 Million Texans
Social Security numbers at risk in state’s largest reported breach since notification law enacted
> AvosLocker Ransomware Striking Critical Infrastructure Targets
US agencies issue IoC alert to help network defenders
> AWS Scaled Command Bash Script - Run AWS commands for many profiles
One area that I have encountered quite often over the years is that during recon phase of a bug bounty hunt or pentest a set of AWS access keys are being discovered. Let’s say you found 50 AWS access keys by drooling and hunting through public Github repos and using other nifty tricks and means. How...
> NFT Fraud in the UK Soars 400% in 2021
English courts praised for giving victims a sympathetic hearing
> Over 40,000 London Voters Have Data Leaked to Strangers
Tory-run Wandsworth Council to blame for email error