Chinese APTs Cash In on Years of Edge Device Attacks

November 1, 2024 at 04:02PM Chinese threat actors have significantly advanced their cyberattack strategies, particularly targeting edge devices. Since 2018, tactics evolved from basic attacks to sophisticated, targeted efforts against high-value organizations. Their recent focus is on stealth and persistence, utilizing advanced malware and exploiting vulnerabilities, demonstrating increased capability in overcoming cybersecurity defenses. ### Meeting … Read more

Massive Git Config Breach Exposes 15,000 Credentials; 10,000 Private Repos Cloned

November 1, 2024 at 07:33AM Cybersecurity researchers have uncovered a campaign, EMERALDWHALE, targeting exposed Git configurations to steal credentials from over 10,000 private repositories. The operation exploits tools to access sensitive files and collect data, leading to extensive credential theft for phishing purposes. A list of 67,000 exposed URLs is being sold online. ### Meeting … Read more

5 SaaS Misconfigurations Leading to Major Fu*%@ Ups

November 1, 2024 at 07:33AM The article discusses key SaaS misconfigurations that pose security risks, including excessive help desk privileges, lack of MFA for super admins, unblocked legacy authentication, mismanaged super admin counts, and Google Groups view settings. It emphasizes the importance of continuous monitoring and fixing these issues to prevent data breaches and ensure … Read more

Gang gobbles 15K credentials from cloud and email providers’ garbage Git configs

October 31, 2024 at 08:04PM Security researchers uncovered a criminal operation named Emeraldwhale, which exposed over 15,000 cloud service and email credentials in an unsecured AWS S3 bucket. The attackers used sophisticated tools to exploit misconfigured servers, targeting Git directories. Although linked to French-speaking malware, Emeraldwhale’s affiliation with a specific criminal group remains unclear. ### … Read more

Noma Launches With Plans to Secure Data, AI Life Cycle

October 31, 2024 at 10:08AM Noma has launched a platform to help organizations manage risks associated with AI applications, securing the AI life cycle against issues like misconfigured pipelines and malicious models. The service works across various environments without requiring code changes. Noma received $32 million in series A funding and serves Fortune 500 clients. … Read more

Microsoft Entra “security defaults” to make MFA setup mandatory

October 30, 2024 at 03:22PM Microsoft will mandate multifactor authentication (MFA) registration for all users when security defaults are enabled, enhancing security across Entra tenants. This requirement, part of the Secure Future Initiative, starts for new tenants on December 2, 2024, and for existing tenants in January 2025, reducing account compromise risks. **Meeting Takeaways: Microsoft … Read more

Hackers steal 15,000 cloud credentials from exposed Git config files

October 30, 2024 at 10:12AM The “EmeraldWhale” operation has exploited exposed Git configuration files to steal over 15,000 cloud credentials from private repositories. Using automated tools, hackers scan IP ranges for vulnerabilities and utilize stolen tokens for phishing and spam. Despite its simplicity, the campaign poses significant risks, prompting developers to adopt better secret management … Read more

Microsoft Warns of Russian Spear-Phishing Attacks Targeting Over 100 Organizations

October 30, 2024 at 09:42AM The 2024 ICS Cybersecurity Conference in Atlanta offers sessions focused on various cybersecurity topics. Stay updated with cybersecurity news, webcasts, and virtual events through SecurityWeek. Subscribe to their email briefing for insights on threats and industry trends, with options to unsubscribe anytime. ### Takeaways from the 2024 ICS Cybersecurity Conference … Read more

China’s ‘Evasive Panda’ APT Debuts High-End Cloud Hijacking

October 29, 2024 at 05:11PM The China-sponsored hacking group Evasive Panda has launched CloudScout, a sophisticated toolset to exploit stolen Web session cookies and access data from cloud services like Google Drive and Gmail. This post-compromise tool evades authentication checks and illustrates the group’s advanced cyberespionage skills targeting civil society and political entities. ### Meeting … Read more

Sophos-SecureWorks Deal Focuses on Building Advanced MDR, XDR Platform

October 28, 2024 at 07:24PM Sophos is acquiring SecureWorks for $859 million to enhance its managed detection and response (MDR) capabilities using SecureWorks’ Taegis platform. This deal aims to strengthen Sophos’ presence in enterprise security services, integrating secure operations while addressing the growing demand for managed security solutions amidst a tight labor market. **Meeting Takeaways: … Read more