Tag AWS

New Cuttlefish Malware Compromises Router Connections to Steal Cloud Credentials

A new cyber threat has emerged, identified as “Cuttlefish,” specifically targeting small office and home office (SOHO) routers. This sophisticated malware aims to covertly monitor all traffic traversing these devices while collecting authentication data from HTTP GET and POST requests. According to a recent report from the Black Lotus Labs…

Read MoreNew Cuttlefish Malware Compromises Router Connections to Steal Cloud Credentials

Non-Human Access: The Path of Least Resistance – A 2023 Overview

New Trends in Cyber Security: The Rising Threat of Non-Human Access As we navigate through 2023, numerous cyber attacks have highlighted a disturbing trend: non-human access is becoming a prevalent attack vector that poses significant security risks to organizations. Recent reports indicate that there have been "11 high-profile attacks in…

Read MoreNon-Human Access: The Path of Least Resistance – A 2023 Overview

Socure Strengthens Identity Services with $136M Acquisition of Effectiv

Socure to Acquire Effectiv: A $136 Million Investment to Enhance Identity Verification Solutions In a strategic move aimed at bolstering its identity verification capabilities, Socure, based in the Lake Tahoe region of Nevada, has announced plans to acquire Effectiv, a startup specializing in risk decisioning. The acquisition, valued at $136…

Read MoreSocure Strengthens Identity Services with $136M Acquisition of Effectiv

Attackers Target Public .env Files to Compromise Cloud Accounts in Extortion Scheme

A significant extortion campaign has emerged, targeting various organizations by exploiting publicly accessible environment variable files (commonly ending in .env) that contain sensitive credentials for cloud and social media applications. This alarming trend underscores the vulnerabilities in data security practices across industries. According to a report by Palo Alto Networks’…

Read MoreAttackers Target Public .env Files to Compromise Cloud Accounts in Extortion Scheme

New “ALBeast” Misconfiguration Reveals Vulnerabilities in AWS Application Load Balancer

Recent investigations have uncovered a significant cybersecurity vulnerability affecting approximately 15,000 applications that utilize Amazon Web Services’ (AWS) Application Load Balancer (ALB) for authentication purposes. This configuration issue could enable malicious actors to bypass access controls, thereby compromising the security of these applications. The research, conducted by the Israeli cybersecurity…

Read MoreNew “ALBeast” Misconfiguration Reveals Vulnerabilities in AWS Application Load Balancer

Data Breach May Compromise Information of Millions from Booking.com and Expedia

Data Breach Exposes Millions of Hotel Customers’ Sensitive Information A significant data breach at Prestige Software, a provider of hotel reservation systems, has potentially compromised the sensitive information of millions of hotel customers. The breach was uncovered by cybersecurity research firm Website Planet, which reported that the company’s Cloud Hospitality…

Read MoreData Breach May Compromise Information of Millions from Booking.com and Expedia

THN Cybersecurity Highlights: Key Threats and Trends (Sept 30 – Oct 6)

Cybersecurity Weekly Recap: Takedowns, DDoS Attacks, and Emerging Threats The realm of cybersecurity continues to evolve with alarming speed, as evidenced by the latest developments in the threat landscape. One significant topic this week is the prevalence of "pig butchering" scams, alongside impactful government interventions and a staggering array of…

Read MoreTHN Cybersecurity Highlights: Key Threats and Trends (Sept 30 – Oct 6)

Cisco Probes Data Breach Following Sale Announcement on BreachForums

A prominent data leaker has claimed to have successfully infiltrated Cisco, a leading networking technology firm, and exfiltrated sensitive company data. This discovery has prompted Cisco to initiate an investigation into the incident. Earlier this week, a cybercriminal operating under the alias IntelBroker took to BreachForums, a well-known hacking marketplace,…

Read MoreCisco Probes Data Breach Following Sale Announcement on BreachForums