This is a story of network segmentation and the impact that seemingly trivial misconfigurations can have for your organization. This is one of those occasions.
This particular pen test asked for goals-based assessment focusing on post-compromise activities — an attempt by the client to discover how vulnerable internal systems were to lateral movement by an attacker who had compromised the domain. Among the goals was a request to attempt to compromise the client’s Amazon Web Services (AWS) infrastructure and a secondary request to access and exploit any systems discovered to contain sensitive or critical operational data .
Read more…
Source: Rapid7
Related:
- Ukraine Cyberattack 2022: Geopolitical Cybersecurity
February 18, 2022
Europe is on a knife-edge. With over 130,000 Russian troops amassed on the Ukrainian border, the region is witnessing the biggest build-up of firepower since the cold war. Inevitably, there is also cyber-dimension to this conflict. Mounting attacks on Ukrainian websites and I.T. infrastructure are making policymakers in Washington and elsewhere nervous should tensions rise ...
- US Government sets forth Zero Trust architecture strategy and requirements
February 17, 2022
To help protect the United States from increasingly sophisticated cyber threats, the White House issued Executive Order (EO) 14028 on Improving the Nation’s Cybersecurity, which requires US Federal Government organizations to take action to strengthen national cybersecurity.1 Section 3 of EO 14028 specifically calls for federal agencies and their suppliers “to modernize approach to ...
- ‘Ice phishing’ on the blockchain
February 16, 2022
The technologies that connect us are continually advancing, and while this brings tremendous new capabilities to users, it also opens new attack surfaces for adversaries and abusers. Social engineering represents a class of threats that has extended to virtually every technology that enables human connection. Our recent analysis of a phishing attack connected to the ...
- Chrome Zero-Day Under Active Attack – Patch ASAP
February 15, 2022
Google on Monday issued 11 security fixes for its Chrome browser, including a high-severity zero-day bug that’s actively being jumped on by attackers in the wild. In a brief update, Google described the weakness, tracked as CVE-2022-0609, as a use-after-free vulnerability in Chrome’s Animation component. This kind of flaw can lead to all sorts of misery, ...
- France opens new business campus to tackle cyberattacks
February 15, 2022
France is grouping the country’s top cybersecurity experts in Paris’ business district of La Defense, bringing together startups and household names to tackle the scourge of hacking, Finance Minister Bruno Le Maire said on Tuesday. Cyberattacks have become the number one worry of the world’s top company executives, according to a survey by PwC, and their ...
- France opens new business campus to tackle cyberattacks
February 15, 2022
France is grouping the country’s top cybersecurity experts in Paris’ business district of La Defense, bringing together startups and household names to tackle the scourge of hacking, Finance Minister Bruno Le Maire said on Tuesday. Cyberattacks have become the number one worry of the world’s top company executives, according to a survey by PwC, and their ...
