Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Dark Reading discusses how confused deputy vulnerabilities remain in Google Cloud and Microsoft Azure, enabling attackers to acquire administrative-level permissions. These flaws bypass cloud providers' access controls, posing significant security risks.
This article discusses persistent 'confused deputy' vulnerabilities in Google Cloud and Microsoft Azure that allow attackers to easily obtain administrative permissions and bypass access controls. It highlights the ongoing risk of privilege escalation in cloud environments.
This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers' access controls.
Confused deputy vulnerabilities persist across major cloud platforms including Google Cloud and Microsoft Azure, enabling attackers to trick one cloud service into acting on behalf of the attacker and acquiring administrative credentials for another service. These cross-tenant confused deputy flaws exploit the trust relationships between cloud services and the way identity and access management tokens are passed between components, allowing adversaries to escalate privileges beyond their authorized scope.
An FBI agent explains how Operation Cronos, a multinational law enforcement effort, successfully disrupted the LockBit ransomware group by breaking trust among its affiliates. The operation's strategy focused on exploiting internal divisions to dismantle the group.
An FBI agent explains how Operation Cronos, a multinational law enforcement effort, successfully disrupted the LockBit ransomware group by breaking trust among its affiliates. The operation's strategy focused on exploiting internal divisions to dismantle the group.