Researchers Uncover Thousands of Leaked AWS Keys
Truffle Security says it found over 9000 publicly accessible and active AWS key pairs
20 articles
Truffle Security says it found over 9000 publicly accessible and active AWS key pairs
TikTok will pay $400 million to settle U.S.
AWS has introduced a new capability for AWS Network Firewall that tracks rule hit counts, providing security teams with direct visibility into how often indi...
AWS Network Firewall’s rule hit count capability gives security teams visibility into which stateful firewall rules are matching traffic, helping them identi...
The U.S.
A large-scale investigation has uncovered 768 publicly exposed AWS access keys that remain active and grant full administrative privileges to corporate cloud...
The flaws have been used by the Head Mare APT hacktivist group to spread PhantomCore malware.
Truffle Security has been tracking this exposure for four years, finding that 817 of the exposed keys were linked to companies, with 526 being AWS root keys.
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [.
Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing.
The U.S.
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal secu...
The Head Mare APT group has been linked to a supply chain compromise involving unpatched TrueConf Server instances, which enabled the delivery of PhantomCore...
U.S.
As firewall rule sets grow in complexity, security teams face a common challenge: manual log analysis is used to determine which rules are actively matching ...
The campaign, primarily impacting devices in Ukraine and Russia, leveraged CVE-2021-33044 and CVE-2021-33045, two authentication-bypass flaws rated 9.8 CVSS ...
The campaign, originating from an IPv6 range provided by LSHIY LLC, leveraged reused credentials and the legacy Resource Owner Password Credentials (ROPC) OA...
Two Artifactory flaws allowed attackers to poison package metadata across software repositories
The AI SAST agent identifies vulnerabilities, including logic flaws missed by traditional tools, and reduces false positives.
Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentica...