Cyber Defense Advisors

Month: May 2023

  • by
  • May 22, 2023

PyPI Repository Under Attack: User Sign-Ups and Package Uploads Temporarily Halted

The maintainers of Python Package Index (PyPI), the official third-party software repository for the Python programming language, have temporarily disabled the ability for users to sign up and upload new packages until further notice. “The volume of malicious users and malicious projects being created on the index in the past week has outpaced our ability […]

Cyber News, Cyber Threat Trends

5 Minute Parent’s Guide to Social Media

The time has come. Your kids are chafing at the bit to get on social media and you can no longer hold them back. But you’re terrified. ‘What if they say the wrong thing? What if they meet some unsavoury types or worst case, what if they get bullied?’ I hear you – everything you […]

Cyber News, Cyber Threat Trends
  • by
  • May 20, 2023

AWS commands still executing with an expired token?

I am running a tool to check configurations in an AWS account. The tool is using an STS session with an assumed role. The role assumption… Continue reading on Bugs That Bite »

Cyber News, Cyber Threat Trends
  • by
  • May 20, 2023

Samsung Devices Under Active Exploitation! CISA Warns of Critical Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of a medium-severity flaw affecting Samsung devices. The issue, tracked as CVE-2023-21492 (CVSS score: 4.4), impacts select Samsung devices running Android versions 11, 12, and 13. The South Korean electronics giant described the issue as an information disclosure flaw that could be exploited by a

Cyber News, Cyber Threat Trends

Okta’s Security Center opens window to customer insights, including threats and friction

The single sign-on market leader’s Security Center, now generally available, uses Okta Customer Identity Cloud for insights into authentication activity for insights into anomalies, threats and security friction. The post Okta’s Security Center opens window to customer insights, including threats and friction appeared first on TechRepublic.

Cyber News, Cyber Threat Trends
  • by
  • May 19, 2023

Unable to locate credentials.

Just a note that you only use source_profile when configuring an AWS CLI profile that assumes a role. Continue reading on Bugs That Bite »

Cyber News, Cyber Threat Trends
  • by
  • May 19, 2023

Critical remote code execution flaws patched in Cisco small business switches

Cisco patched several vulnerabilities this week that affect multiple models of its small business switches and could allow attackers to take full control of the devices remotely. The flaws are all located in the web-based management interface of the devices and can be exploited without authentication. While the company didn’t disclose which specific components of […]

Cyber News, Cyber Threat Trends
  • by
  • May 19, 2023

Trojan-Rigged Phishing Attacks Pepper China-Taiwan Conflict

Plug X and other information-stealing remote-access Trojans are among the malware targeting networking, manufacturing, and logistics companies in Taiwan.

Cyber News, Cyber Threat Trends