Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
What's Hot

Astrophysics of Multi-Absorbing Audience, Muong, Mississippi

Filless Remcos rats delivered via LNK files and MSHTA in PowerShell-based attacks

Trump’s decision to lift Syria sanctions burns dreams of reviving the economy | Politics News

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Español
    • Português
Fyself News
Home » Trust Beyondtrust Zero Day British to expose 17 SaaS customers via the infringed API key
Identity

Trust Beyondtrust Zero Day British to expose 17 SaaS customers via the infringed API key

userBy userFebruary 1, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

LingeringFebruary 1, 2025LingeringRavy LakshmananVulnerability /zero day

Beyond the zero day violation

BeyondTrust has revealed that the recent survey of recent cyber security cases for part of the company’s remote support SaaS instance using the infringed API key.

The company stated that the violation contained 17 remote support SaaS customers, and that the API key was used to reset local application passwords to enable unauthorized access. The violation was first flagged on December 5, 2024.

“In the survey, it was determined that the zero -day vulnerability for the third party application was used and the Trust AWS BEYOND AWS account had gained access to online assets,” said the company this week.

“With access to the assets, threat actors can use the infrastructure API key and use it for another AWS account that operates remote support infrastructure.”

Cyber ​​security

The American Access Management Company did not name the applications surveyed to get the API key, but this probe has two different products (CVE-2024-12356 and CVE-2024-12686). He said he had found a defect.

Since then, Trust Beyond has canceled the compromised API key, has stopped all the affected customer instances, and provides an alternative remote support SaaS instance.

The US Cyber ​​Security and Infrastructure Security Bureau (CISA) add CVE-2024-12356 and CVE-2024-12686 to the known vulnerabilities (KEV) catalog, and evidence of active exploitation in the wild. Quoting is worth noting. The exact details of malicious activities are currently unknown.

This development occurs as the US Treasury states that it is one of the affected parties. Other federal agencies have not been evaluated as affected.

The attack is due to the Hacking Guroup (former Huffnium) linked to China, called Silk Typone (formerly Huffnium), and the agency is suspected of violating the Ministry of Finance’s office network. It imposes sanctions on a cyber actor named Yin Kecheng.

Did you find this article interesting? Follow on Twitter and Linkedin and read the exclusive content to post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleRussia -Ukurain War: List of Major Events -Day 1,073 | News of the Russian Ukelaine War
Next Article Hamas will release three Israeli prisoners in exchange for 183 Palestinians | Israel and Palestinian conflict news
user
  • Website

Related Posts

Filless Remcos rats delivered via LNK files and MSHTA in PowerShell-based attacks

May 16, 2025

Meta will train AI on EU user data from May 27th without consent. Noyb threatens lawsuits

May 15, 2025

Coinbase Agent has been bribed, ~1% of users’ data leaked. 20 million dollar terr attempt fails

May 15, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Astrophysics of Multi-Absorbing Audience, Muong, Mississippi

Filless Remcos rats delivered via LNK files and MSHTA in PowerShell-based attacks

Trump’s decision to lift Syria sanctions burns dreams of reviving the economy | Politics News

US Senators are trying to block Trump’s UAE, Qatar defense contract | Donald Trump News

Trending Posts

Trump’s decision to lift Syria sanctions burns dreams of reviving the economy | Politics News

May 16, 2025

US Senators are trying to block Trump’s UAE, Qatar defense contract | Donald Trump News

May 16, 2025

What is hunger, and why is Gaza at risk of reaching it soon? | Israeli-Palestinian conflict news

May 16, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Top tech startup funding news for today, May 15, 2025

AI video startup Hedra Lands Helps the $32 million Lands brand, led by Andreessen Horowitz, create realistic digital avatars

2025 Digital Security Landscape: Major AI Trends and Emerging Challenges

AI Food Technology Startup MetaFoodx raises $9.4 million to tackle $38.2 billion in kitchen waste with 3D scans

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.