44M Digital Wallet Items Exposed in Key Ring Cloud Misconfig

Millions of IDs, charge cards, loyalty cards, gift cards, medical marijuana ID cards and personal information was left exposed to the open internet. Continue reading 44M Digital Wallet Items Exposed in Key Ring Cloud Misconfig

The Threat in the Cloud: Phishing Abuses Amazon AWS S3 Buckets

An ongoing campaign is hosting its phishing landing pages on enterprise-class public cloud storage services — a nascent trend meant to throw defenders off. Continue reading The Threat in the Cloud: Phishing Abuses Amazon AWS S3 Buckets

Magecart Actors Using Spray and Pray Tactics to Find Misconfigured Buckets

Magecart actors are using spray and pray tactics to discover misconfigured Amazon S3 buckets and deploy their payment card skimmers. In April 2019, RiskIQ began tracking a Magecart group campaign in which threat actors took to automatically scanning fo… Continue reading Magecart Actors Using Spray and Pray Tactics to Find Misconfigured Buckets

Taming the Jungle: Hardening your AWS infrastructure

After nine tutorials, sixteen posts on stack overflow, and several hours or workweeks of effort you’ve finally done it. You’ve finally got something in Amazon Web Services (AWS) to work as expected. It could have been something as simple as… Continue reading Taming the Jungle: Hardening your AWS infrastructure

Everything You Need to Know About Azure Infrastructure – April 2019 Edition


In my monthly summary, I will summarize all the Azure infrastructure news from April, which appeared to be a month for security announcements.

The post Everything You Need to Know About Azure Infrastructure – April 2019 Edition appeared first on Petri.

Continue reading Everything You Need to Know About Azure Infrastructure – April 2019 Edition

Insurance Software Provider Exposed Clients’ Data Stored on S3 Bucket

An insurance software provider exposed clients’ sensitive data that it had stored on an Amazon Simple Storage Solution (S3) bucket. Andrew Lech, founder of AgentRun, confirmed the breach in an email sent out to the insurance agency management sof… Continue reading Insurance Software Provider Exposed Clients’ Data Stored on S3 Bucket