Cyber Defense Advisors

Year: 2023

  • by
  • May 20, 2023

AWS commands still executing with an expired token?

I am running a tool to check configurations in an AWS account. The tool is using an STS session with an assumed role. The role assumption… Continue reading on Bugs That Bite »

Cyber News, Cyber Threat Trends
  • by
  • May 20, 2023

Samsung Devices Under Active Exploitation! CISA Warns of Critical Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned of active exploitation of a medium-severity flaw affecting Samsung devices. The issue, tracked as CVE-2023-21492 (CVSS score: 4.4), impacts select Samsung devices running Android versions 11, 12, and 13. The South Korean electronics giant described the issue as an information disclosure flaw that could be exploited by a

Cyber News, Cyber Threat Trends

Okta’s Security Center opens window to customer insights, including threats and friction

The single sign-on market leader’s Security Center, now generally available, uses Okta Customer Identity Cloud for insights into authentication activity for insights into anomalies, threats and security friction. The post Okta’s Security Center opens window to customer insights, including threats and friction appeared first on TechRepublic.

Cyber News, Cyber Threat Trends
  • by
  • May 19, 2023

Unable to locate credentials.

Just a note that you only use source_profile when configuring an AWS CLI profile that assumes a role. Continue reading on Bugs That Bite »

Cyber News, Cyber Threat Trends
  • by
  • May 19, 2023

Critical remote code execution flaws patched in Cisco small business switches

Cisco patched several vulnerabilities this week that affect multiple models of its small business switches and could allow attackers to take full control of the devices remotely. The flaws are all located in the web-based management interface of the devices and can be exploited without authentication. While the company didn’t disclose which specific components of […]

Cyber News, Cyber Threat Trends
  • by
  • May 19, 2023

Trojan-Rigged Phishing Attacks Pepper China-Taiwan Conflict

Plug X and other information-stealing remote-access Trojans are among the malware targeting networking, manufacturing, and logistics companies in Taiwan.

Cyber News, Cyber Threat Trends
  • by
  • May 19, 2023

KeePass Vulnerability Imperils Master Passwords

A newly discovered bug in the open source password manager, if exploited, lets attackers retrieve a target’s master password — and proof-of-concept code is available.

Cyber News, Cyber Threat Trends
  • by
  • May 19, 2023

Enterprises Rely on Multicloud Security to Protect Cloud Workloads

As enterprises adopt multicloud, the security picture has gotten foggy. Cloud workload protection platforms and distributed firewalls are creating clarity.

Cyber News, Cyber Threat Trends