After leveraging a zero-day within a third-party app to compromise a BeyondTrust AWS account asset, attackers proceeded to exploit the asset to secure an infrastructure API key that was then utilized to control another AWS account for managing Remote Support infrastructure, according to BeyondTrust's investigation.
In a letter sent to Congressional leaders, the organizations argued that a national privacy standard would benefit businesses by reducing regulatory complexity and promoting competition, which could lower costs and increase consumer access.
The US Court of Appeals has vacated the original sentence of Conor Brian Fitzpatrick, also known as Pompompurin, who is the founder of the BreachForums cybercrime marketplace.
The breach occurred when attackers exploited a stolen account credential to access PowerSchool’s customer support portal and proceed to steal vast amounts of sensitive data.
A lot of AI security boils down to the boring, but important, software security topics that appsec teams have been dealing with for decades. Niv Braun explains the distinctions between AI-related and AI-specific security as we avoid the FUD and hype of genAI to figure out where appsec teams can invest their time. He notes that data scientists have ...
After inputting valid employee emails to infiltrate Starlink's admin panel hosted on a subarucs.com subdomain, threat actors could perform password resets, omit client-side overlay, and evade two-factor authentication to access the panel's features and determine different types of customer and vehicle information, including names, vehicle identification numbers, and location details.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.