A subtle flaw, a massive blast radius. [Research Saturday]
CyberWire Daily21 Maalis

A subtle flaw, a massive blast radius. [Research Saturday]

Yuval Avrahami from Wiz joins to share their work on "CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild." Wiz Research uncovered “CodeBreach,” a critical supply chain vulnerability caused by a subtle misconfiguration in AWS CodeBuild pipelines that allowed attackers to take over key GitHub repositories, including the widely used AWS JavaScript SDK that powers the AWS Console. By exploiting an unanchored regex filter, unauthenticated attackers could trigger privileged builds, steal credentials, and potentially inject malicious code into software used across a majority of cloud environments. AWS has since remediated the issue and introduced stronger safeguards, but the incident highlights a growing trend of attackers targeting CI/CD pipelines where small misconfigurations can lead to massive downstream impact. The research can be found here: CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(3739)

The blacklist boomerang.

The blacklist boomerang.

A judge rules the Trump administration illegally labeled Anthropic a national security risk. The White House moves to keep foreign technology out of U.S. power systems. OpenAI rallies a global cyber d...

28 Elo 29min

Meta gets a Meta-sized bill.

Meta gets a Meta-sized bill.

Meta settles. Australian police arrest two alleged TeamPCP members. The White House moves to shore up water utility cybersecurity. ATF reports a major cyber incident. The Navy tells sailors to lock do...

27 Elo 31min

The feds flip the script.

The feds flip the script.

The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies. CISA says more than 100 water systems were targeted in July. Attackers exploit a critical...

26 Elo 32min

CISA is running on empty.

CISA is running on empty.

Lawmakers request an investigation into cuts at CISA. Threat actors actively exploit a Zimbra Collaboration Suite vulnerability. A Chinese AI lab preps release of a powerful open-weight model. A new p...

25 Elo 28min

The odds were classified.

The odds were classified.

Polymarket traders win big on U.S. military insider information. Slovakia deactivates speed cameras with Russian backdoors. TikTok pays $400 million to settle kids' privacy allegations. Hackers infect...

24 Elo 30min

Building a secure space internet. [T-Minus: Space-Cyber Briefing]

Building a secure space internet. [T-Minus: Space-Cyber Briefing]

As space infrastructure has continued to expand, developing secure space systems has become just as important as launching the spacecraft themselves. In this week's episode, host Maria Varmazis sits ...

23 Elo 24min

A RAT in the spreadsheet. [Research Saturday]

A RAT in the spreadsheet. [Research Saturday]

Today we are joined by Aaron Beardslee, Manager of Threat Research at Securonix, discussing "Analyzing SHEET#CREEP: SHEETCREEP is up again with different config obfuscation." Securonix researchers hav...

22 Elo 29min

The guest nobody invited.

The guest nobody invited.

CISA orders patching of TrueConf Server vulnerabilities. LockBit threatens release of stolen banking data. Researchers disclose a critical type confusion vulnerability in a Node.js library. A new Agen...

21 Elo 31min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
politiikan-puskaradio
ootsa-kuullut-tasta-2
rss-ootsa-kuullut-tasta
rss-vaalirankkurit-podcast
otetaan-yhdet
rss-podme-livebox
rss-voi-venaja
politbyroo
tervo-halme
rss-seksicast
rss-kaikki-uusiksi
rss-girls-finish-f1rst
rss-asiastudio
rss-kovin-paikka
linda-maria
nakokulma-oikealta-jussi-halla-ahon-blogin-kommentaarit
rss-pinnalla
rss-raha-talous-ja-politiikka