ShinyHunters, the data theft and extortion crew that has stolen sensitive information belonging to millions of cancer patients, university and K-12 students, and Carnival cruisers, wanted to preserve…
SentinelOne has announced the expansion of Wayfinder Threat Hunting to the major public cloud services: AWS, Azure, and Google Cloud. It’s the latest offering from SentinelOne’s Wayfinder team and…
It was discovered that OpenStack Swift incorrectly handled truncated aws-chunked PUT request bodies in its s3api middleware. An authenticated attacker could possibly use this issue to cause OpenStack…
ShinyHunters Claims Access to FBI Systems Days after hijacking Clop’s Dark Web leak site, ShinyHunters claims it breached the FBI, defaced part of its recruitment website, and stole sensitive…
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According…
ShinyHunters claims it hacked the FBI and stole more than 2 TB of employee data - and this time it’s personal. The gang wants the Feds to correct the record on how it operates. “This is NOT…
Serverless, Not Riskless: Exploiting Unauthenticated API Gateways in AWS September 21, 2026 sara.pearlman@guidepointsecurity.com BLOG 5 min. Over the past year, GuidePoint’s Threat and Attack…
Analyser une compromission sur Amazon EKS revient à reconstituer des preuves réparties sur trois couches : le control plane Kubernetes managé, les nodes workers et les services AWS environnants. Cet…
Historiquement réservé au secteur bancaire, le processus de KYC (Know Your Customer) s'impose aujourd'hui à de nombreux services en ligne, propulsé par des législations toujours plus strictes sur…
De nos jours, il est rare de trouver une entreprise dont le système informatique ne repose pas, au moins en partie, sur les technologies cloud. Ces solutions offrent de nombreux avantages, notamment…
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for…
Run security operations for more than one team, region, or customer, and you inherit a familiar tradeoff. One giant deployment gives you a single view but costs you tenant isolation, while separate…
This post will explore what this new concept does, how it works with the new Account Access capability, and why a strong security posture still requires upgrading out of the sandbox.
Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain and the UAE. In two…
Simplify Threat Intelligence Procurement with SOCRadar and Microsoft Marketplace Your security team has already made the case for external threat intelligence. The budget owner agrees. Then the deal…