US Treasury Reports Record $4.5B in Ransomware Payments While React2Shell Active Exploitation Spikes and Threat Actors Deploy Shana.exe Packer to Evade EDR Detection
Solid rundown of today's threat landscape. The AWS IAM eventual consistency angle is particuarly scary becaue it's not even a vulnerability in the traditional sense, just a design trade-off that attackers figured out how to weaponize. Makes me wonder how many other cloud platform 'features' are waiting to be abused inthe same way.
Solid rundown of today's threat landscape. The AWS IAM eventual consistency angle is particuarly scary becaue it's not even a vulnerability in the traditional sense, just a design trade-off that attackers figured out how to weaponize. Makes me wonder how many other cloud platform 'features' are waiting to be abused inthe same way.
The AWS vector is scary and from history we know, our streamlining of business will be the next attack vector.