This is a story of network segmentation and the impact that seemingly trivial misconfigurations can have for your organization. This is one of those occasions.
This particular pen test asked for goals-based assessment focusing on post-compromise activities — an attempt by the client to discover how vulnerable internal systems were to lateral movement by an attacker who had compromised the domain. Among the goals was a request to attempt to compromise the client’s Amazon Web Services (AWS) infrastructure and a secondary request to access and exploit any systems discovered to contain sensitive or critical operational data .
Read more…
Source: Rapid7
Related:
- Apple Releases Security Updates for Multiple Products
March 28, 2023
Apple has released security updates to address vulnerabilities in multiple products. An attacker could exploit some of these vulnerabilities to take control of an affected device. CISA encourages users and administrators to review the following advisories and apply the necessary updates. Read more… Source: U.S. Cybersecurity and Infrastructure Security Agency
- Maldives to set up network to tackle cybercrime
March 28, 2023
Amendments have been submitted to the Act on Mutual Legal Assistance in Criminal Matters, designed to set up procedures for exchange of legal assistance with other countries in order to stop and take action against cybercrimes, crimes committed using computer systems, and crimes that involve electronic evidence. Presenting the bill, Haitham noted the increase in crimes ...
- White House ‘very in favor’ of bill thought to target TikTok
March 26, 2023
One of the authors of a Senate bill that would enable the US commerce department to ban technologies with links to foreign governments has said the Biden White House is “very in favor” of the measure, but stopped short of saying whether the administration has discussed possibly prohibiting the Chinese-owned platform TikTok in particular. Appearing on ...
- Business Email Compromise Tactics Used to Facilitate the Acquisition of Commodities and Defrauding Vendors
March 24, 2023
The FBI warns the public of criminal actors using Business Email Compromise (BEC) schemes to facilitate the acquisition of a wide range of commodities. BEC is one of the most financially damaging online crimes. It exploits the fact that so many of us rely on email to conduct business—both personal and professional. In many BEC scams, ...
- UK: TikTok to be blocked from parliamentary devices and network over cyber security fears
March 23, 2023
The commissions of the House of Commons and House of Lords have announced they will follow the move taken by the government on official devices, citing the need for cyber security. A parliament spokesman said that TikTok “will be blocked from all parliamentary devices and the wider parliamentary network”. Read more… Source: Sky News
- Untitled Goose Tool Aids Hunt and Incident Response in Azure, Azure Active Directory, and Microsoft 365 Environments
March 23, 2023
Today, CISA released the Untitled Goose Tool to help network defenders detect potentially malicious activity in Microsoft Azure, Azure Active Directory (AAD), and Microsoft 365 (M365) environments. The Untitled Goose Tool offers novel authentication and data gathering methods for network defenders to use as they interrogate and analyze their Microsoft cloud services. The tool enables ...
