Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

How Brex is catching up to AI by embracing “confusion”

Adaptive Reuse Creates Homes in Suburban Texas Strip Malls

Investigation: Anti-homelessness laws don’t work

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Trust Beyondtrust Zero Day British to expose 17 SaaS customers via the infringed API key
Identity

Trust Beyondtrust Zero Day British to expose 17 SaaS customers via the infringed API key

userBy userFebruary 1, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

LingeringFebruary 1, 2025LingeringRavy LakshmananVulnerability /zero day

Beyond the zero day violation

BeyondTrust has revealed that the recent survey of recent cyber security cases for part of the company’s remote support SaaS instance using the infringed API key.

The company stated that the violation contained 17 remote support SaaS customers, and that the API key was used to reset local application passwords to enable unauthorized access. The violation was first flagged on December 5, 2024.

“In the survey, it was determined that the zero -day vulnerability for the third party application was used and the Trust AWS BEYOND AWS account had gained access to online assets,” said the company this week.

“With access to the assets, threat actors can use the infrastructure API key and use it for another AWS account that operates remote support infrastructure.”

Cyber ​​security

The American Access Management Company did not name the applications surveyed to get the API key, but this probe has two different products (CVE-2024-12356 and CVE-2024-12686). He said he had found a defect.

Since then, Trust Beyond has canceled the compromised API key, has stopped all the affected customer instances, and provides an alternative remote support SaaS instance.

The US Cyber ​​Security and Infrastructure Security Bureau (CISA) add CVE-2024-12356 and CVE-2024-12686 to the known vulnerabilities (KEV) catalog, and evidence of active exploitation in the wild. Quoting is worth noting. The exact details of malicious activities are currently unknown.

This development occurs as the US Treasury states that it is one of the affected parties. Other federal agencies have not been evaluated as affected.

The attack is due to the Hacking Guroup (former Huffnium) linked to China, called Silk Typone (formerly Huffnium), and the agency is suspected of violating the Ministry of Finance’s office network. It imposes sanctions on a cyber actor named Yin Kecheng.

Did you find this article interesting? Follow on Twitter and Linkedin and read the exclusive content to post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleRussia -Ukurain War: List of Major Events -Day 1,073 | News of the Russian Ukelaine War
Next Article Hamas will release three Israeli prisoners in exchange for 183 Palestinians | Israel and Palestinian conflict news
user
  • Website

Related Posts

Taiwan NSB warns the public about the risks of data reintroducing Tiktok, Waibo and Chinese ties

July 5, 2025

The exposed JDWP interface leads to crypto mining, and Hpingbot targets DDO’s SSH

July 5, 2025

TwinH: A New Frontier in the Pursuit of Immortality?

July 4, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

How Brex is catching up to AI by embracing “confusion”

Adaptive Reuse Creates Homes in Suburban Texas Strip Malls

Investigation: Anti-homelessness laws don’t work

In the US, urban gondolas face uphill battles

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

TwinH: A New Frontier in the Pursuit of Immortality?

Meta’s Secret Weapon: The Superintelligence Unit That Could Change Everything 

Unlocking the Power of Prediction: The Rise of Digital Twins in the IoT World

TwinH: Digital Human Twin Aims for Victory at Break the Gap 2025

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.