Mandiant
|
cybersecurity
|
Mar 17, 2026
Hackers "enumerated and accessed objects within S3 buckets, terminated production EC2 and RDS instances, and decrypted application keys."
The threat actor has been moving laterally, stealing user tokens and maintaining persistence via a range of techniques.
"The core vulnerability is a help desk process that lacks robust, non-transferable identity verification for password resets..."
Threat actor decrypts malicious payloads and executes them in memory, leaving 'minimal forensic traces.'
Mandiant
|
Mar 24, 2024
Russia's Cozy Bear hacking operation is changing up its tactics to go after political parties in Germany