Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Malicious NGINX configuration enables massive web traffic hijacking campaign

Sam Altman took a very harsh stance on Claude’s Super Bowl ad

Revenue increases in Q4 as Snap prepares for general availability, but daily users decline

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Trust Beyondtrust Zero Day British to expose 17 SaaS customers via the infringed API key
Identity

Trust Beyondtrust Zero Day British to expose 17 SaaS customers via the infringed API key

userBy userFebruary 1, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

LingeringFebruary 1, 2025LingeringRavy LakshmananVulnerability /zero day

Beyond the zero day violation

BeyondTrust has revealed that the recent survey of recent cyber security cases for part of the company’s remote support SaaS instance using the infringed API key.

The company stated that the violation contained 17 remote support SaaS customers, and that the API key was used to reset local application passwords to enable unauthorized access. The violation was first flagged on December 5, 2024.

“In the survey, it was determined that the zero -day vulnerability for the third party application was used and the Trust AWS BEYOND AWS account had gained access to online assets,” said the company this week.

“With access to the assets, threat actors can use the infrastructure API key and use it for another AWS account that operates remote support infrastructure.”

Cyber ​​security

The American Access Management Company did not name the applications surveyed to get the API key, but this probe has two different products (CVE-2024-12356 and CVE-2024-12686). He said he had found a defect.

Since then, Trust Beyond has canceled the compromised API key, has stopped all the affected customer instances, and provides an alternative remote support SaaS instance.

The US Cyber ​​Security and Infrastructure Security Bureau (CISA) add CVE-2024-12356 and CVE-2024-12686 to the known vulnerabilities (KEV) catalog, and evidence of active exploitation in the wild. Quoting is worth noting. The exact details of malicious activities are currently unknown.

This development occurs as the US Treasury states that it is one of the affected parties. Other federal agencies have not been evaluated as affected.

The attack is due to the Hacking Guroup (former Huffnium) linked to China, called Silk Typone (formerly Huffnium), and the agency is suspected of violating the Ministry of Finance’s office network. It imposes sanctions on a cyber actor named Yin Kecheng.

Did you find this article interesting? Follow on Twitter and Linkedin and read the exclusive content to post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleRussia -Ukurain War: List of Major Events -Day 1,073 | News of the Russian Ukelaine War
Next Article Hamas will release three Israeli prisoners in exchange for 183 Palestinians | Israel and Palestinian conflict news
user
  • Website

Related Posts

Malicious NGINX configuration enables massive web traffic hijacking campaign

February 5, 2026

Microsoft develops scanner to detect backdoors in open weight large-scale language models

February 4, 2026

DEAD#VAX malware campaign deploys AsyncRAT via VHD phishing files hosted on IPFS

February 4, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Malicious NGINX configuration enables massive web traffic hijacking campaign

Sam Altman took a very harsh stance on Claude’s Super Bowl ad

Revenue increases in Q4 as Snap prepares for general availability, but daily users decline

Alphabet won’t tell investors about Google and Apple’s AI deal

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.