home.social

#attacksurface — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #attacksurface, aggregated by home.social.

fetched live
  1. Annual pentests aren’t enough: a bank’s vendor mortgage portal left staff data exposed via unauthenticated API for 345 days. No CVE, but impact is HIGH. Continuous testing and asset monitoring are essential. radar.offseq.com/threat/what-3 #OffSeq #InfoSec #Banking #AttackSurface

  2. Identity Exposures Form Highways for Cyber Attacks

    A single compromised identity can become a superhighway for cyber attacks, giving hackers access to nearly every critical workload a business relies on - as seen in a recent incident where a cached AWS access key on one Windows machine put 98% of the company's cloud environment at risk. Identity has become the ultimate attack path, carrying…

    osintsights.com/identity-expos

    #CloudSecurity #IdentityManagement #CredentialExposure #Aws #AttackSurface

  3. Advanced Subdomain Discovery with Amass and Cheat Sheet

    In this cheat sheet, I cover essential Amass commands, enumeration techniques, and practical workflows for effective recon.
    denizhalil.com/2026/05/02/owas

    #CyberSecurity #OWASP #Amass #SubdomainEnumeration #Recon #OSINT #AttackSurface #BugBounty

  4. Advanced Subdomain Discovery with Amass and Cheat Sheet

    In this cheat sheet, I cover essential Amass commands, enumeration techniques, and practical workflows for effective recon.
    denizhalil.com/2026/05/02/owas

    #CyberSecurity #OWASP #Amass #SubdomainEnumeration #Recon #OSINT #AttackSurface #BugBounty

  5. Subdomain Takeover Vulnerabilities and Prevention

    In this article, I cover:
    * How subdomain takeover vulnerabilities occur
    * Real-world exploitation scenarios
    Reconnaissance and detection techniques
    * Practical prevention and DNS hygiene strategies

    denizhalil.com/2026/02/16/subd

    #CyberSecurity #SubdomainTakeover #DNS #AttackSurface #BugBounty #RedTeam #BlueTeam #InfoSec #CloudSecurity #WebSecurity #EthicalHacking

  6. Subdomain Takeover Vulnerabilities and Prevention

    In this article, I cover:
    * How subdomain takeover vulnerabilities occur
    * Real-world exploitation scenarios
    Reconnaissance and detection techniques
    * Practical prevention and DNS hygiene strategies

    denizhalil.com/2026/02/16/subd

    #CyberSecurity #SubdomainTakeover #DNS #AttackSurface #BugBounty #RedTeam #BlueTeam #InfoSec #CloudSecurity #WebSecurity #EthicalHacking

  7. Security Advisory Summary:
    SolarWinds Serv-U 15.5.4 patches four critical vulnerabilities:
    • CVE-2025-40538 – Broken access control → system admin creation + root RCE
    • Two type confusion flaws → root code execution
    • One IDOR vulnerability → elevated execution

    Attack prerequisites:
    High-privileged access required. Exploitation likely via credential compromise or chained privilege escalation.

    Exposure landscape:
    12K+ internet-facing instances observed (Shodan)
    File transfer platforms remain ransomware-favored entry vectors

    Historical context:
    Prior Serv-U CVEs exploited by ransomware groups and state-aligned actors.

    Immediate actions:
    - Patch to 15.5.4
    - Audit privileged accounts
    - Review FTP/SFTP exposure
    - Monitor for anomalous admin creation

    Source: bleepingcomputer.com/news/secu

    Follow us for tactical advisories and vulnerability intelligence.

    Comment with your detection or hardening recommendations.

    #Infosec #SolarWinds #ThreatIntel #CVE2025 #RCE #PrivilegeEscalation #BlueTeam #SecurityEngineering #AttackSurface #ZeroTrust

  8. Active exploitation is being observed via misconfigured security testing applications, enabling attackers to move from exposed training tools into cloud environments.

    The issue centers on excessive IAM permissions, default credentials, and poor isolation between test and sensitive systems - not novel malware.

    This reinforces the need to treat non-production assets as part of the threat surface.

    Source: bleepingcomputer.com/news/secu

    Follow @technadu for neutral, research-driven security reporting.

    #CloudSecurity #IAM #Pentesting #Infosec #AttackSurface #TechNadu

  9. Brash - architectural Blink flaw that enables Chromium collapse; defensive checklist

    The Brash research highlights a core Blink design gap: unthrottled document.title updates can saturate the main thread. Impact spans desktop browsers, embedded Chromium runtimes and headless agents. Vendors are expected to patch; until then, defenders should:
    • Inventory Chromium runtimes and headless agents.
    • Add process-level CPU/latency alerts for browser processes.
    • Monitor automation pipelines for simultaneous headless failures.
    • Implement circuit breakers for critical UIs and fallbacks for automation.
    • Harden email/portal gating to reduce timed-trigger links reaching many users simultaneously.

    Share detection tactics you’ve tested. Follow @technadu for deeper coverage and technical playbooks.

    #Infosec #ThreatIntel #Chromium #BrowserSecurity #EDR #Headless #AttackSurface

  10. „One day my son,
    all this #AttackSurface
    will be yours!“

  11. „One day my son,
    all this #AttackSurface
    will be yours!“

  12. Chapter No.312 in the "AI is useless piece of shit with no use cases"

    Prompt:
    "I want you to add all the attack vectors, patterns and algorithms for NginX, Wordpress, Cadvisor... etc... Can you pull them from the web for me? I want a swiss army knife nginx error log parser"

    Output:
    <Creates a log parser bash script ready to feed prometheus telemetry for Grafana monitoring> ...

    Is it perfect?
    Fsck no.
    Is it good enough for my #selfhosted #attacksurface telementry?
    Fsck Yes.

    #OWASP #Vibecoding #Grafana #PromptEngineering #GitGud

  13. 🎯 NOW PUBLISHING: On-Location Coverage from #BlackHatUSA 2025!

    We're back in the office and excited to start sharing all the conversations we captured on location in Las Vegas with our amazing sponsors and editorial coverage!

    🔔 Follow ITSPmagazine, Sean Martin, CISSP, and Marco Ciappelli to get this content fresh as it drops!

    We're honored to share this eye-opening Brand Story conversation thanks to our friends at runZero 🙏

    The Often-Overlooked Truth in #Cybersecurity: Seeing the Unseen in Vulnerability Management

    Most successful breaches don't happen because defenders ignored known vulnerabilities. They happen because attackers exploited assets that organizations never knew existed.

    HD‏​​​​​​​​​​‏ ⁢​​​​Moore, founder and CEO of runZero and creator of #Metasploit, reveals the uncomfortable truth: organizations routinely miss half their actual attack surface. Through decades of penetration testing high-security environments, Moore discovered that traditional discovery methods only find properly managed systems while #shadowIT, legacy hardware, and misconfigured devices remain invisible.

    Key insights from our conversation:

    • When using attacker-grade discovery techniques, asset counts typically DOUBLE what organizations thought they had

    • The industry's CVE obsession creates false security while real attacks exploit misconfigurations and zero-days

    • Unknown assets—from IoT devices to forgotten servers—bypass even sophisticated security controls

    • Traditional agent-based tools can't see what attackers see

    #RunZero inverts the traditional model by starting with unauthenticated discovery that mirrors how attackers actually probe networks. This reveals the true attack surface and transforms vulnerability management from reactive patching to strategic risk reduction.

    📺 Watch the video: youtu.be/hkKJsKUugIU

    🎧 Listen to the podcast: brand-stories-podcast.simpleca 📖 Read the blog: itspmagazine.com/their-stories

    ➤ Learn more about RunZero: itspm.ag/runzero-5733

    ✦ Catch more stories from RunZero: itspmagazine.com/directory/run

    🎪 Follow all of our #BHUSA 2025 coverage: itspmagazine.com/bhusa25

    #Cybersecurity #VulnerabilityManagement #AssetDiscovery #AttackSurface #BlackHatUSA #BHUSA25 #ShadowIT #SecurityVisibility #Metasploit #ZeroDay #tech #technology #cybersecurity

  14. 🎯 NOW PUBLISHING: On-Location Coverage from #BlackHatUSA 2025!

    We're back in the office and excited to start sharing all the conversations we captured on location in Las Vegas with our amazing sponsors and editorial coverage!

    🔔 Follow ITSPmagazine, Sean Martin, CISSP, and Marco Ciappelli to get this content fresh as it drops!

    We're honored to share this eye-opening Brand Story conversation thanks to our friends at runZero 🙏

    The Often-Overlooked Truth in #Cybersecurity: Seeing the Unseen in Vulnerability Management

    Most successful breaches don't happen because defenders ignored known vulnerabilities. They happen because attackers exploited assets that organizations never knew existed.

    HD‏​​​​​​​​​​‏ ⁢​​​​Moore, founder and CEO of runZero and creator of #Metasploit, reveals the uncomfortable truth: organizations routinely miss half their actual attack surface. Through decades of penetration testing high-security environments, Moore discovered that traditional discovery methods only find properly managed systems while #shadowIT, legacy hardware, and misconfigured devices remain invisible.

    Key insights from our conversation:

    • When using attacker-grade discovery techniques, asset counts typically DOUBLE what organizations thought they had

    • The industry's CVE obsession creates false security while real attacks exploit misconfigurations and zero-days

    • Unknown assets—from IoT devices to forgotten servers—bypass even sophisticated security controls

    • Traditional agent-based tools can't see what attackers see

    #RunZero inverts the traditional model by starting with unauthenticated discovery that mirrors how attackers actually probe networks. This reveals the true attack surface and transforms vulnerability management from reactive patching to strategic risk reduction.

    📺 Watch the video: youtu.be/hkKJsKUugIU

    🎧 Listen to the podcast: brand-stories-podcast.simpleca 📖 Read the blog: itspmagazine.com/their-stories

    ➤ Learn more about RunZero: itspm.ag/runzero-5733

    ✦ Catch more stories from RunZero: itspmagazine.com/directory/run

    🎪 Follow all of our #BHUSA 2025 coverage: itspmagazine.com/bhusa25

    #Cybersecurity #VulnerabilityManagement #AssetDiscovery #AttackSurface #BlackHatUSA #BHUSA25 #ShadowIT #SecurityVisibility #Metasploit #ZeroDay #tech #technology #cybersecurity

  15. Everyone's making final updates for the initial release of @owasp Amass v5!

    Register and join our workshop at @defcon for additional details: lu.ma/hf83v61c

    #security #infosec #redteam #recon #osint #attacksurface @defconowasp

  16. Everyone's making final updates for the initial release of @owasp Amass v5!

    Register and join our workshop at @defcon for additional details: lu.ma/hf83v61c

    #security #infosec #redteam #recon #osint #attacksurface @defconowasp

  17. From the ADMIN Update newsletter: Learn how the tools used in attack surface management help identify attack surfaces more precisely and respond to changes in risk situations
    admin-magazine.com/Archive/202
    #ASM #tools #vulnerabilities #security #AttackSurface #SaaS

  18. From the ADMIN Update newsletter: Learn how the tools used in attack surface management help identify attack surfaces more precisely and respond to changes in risk situations
    admin-magazine.com/Archive/202
    #ASM #tools #vulnerabilities #security #AttackSurface #SaaS

  19. If you're planning to attend @defcon 33, and would like to quickly get up to speed on the upcoming Amass v5.0 release, then please consider registering for this workshop being hosted in the @owasp Community Room!

    #security #infosec #owasp #recon #osint #DEFCON #attacksurface

    lu.ma/hf83v61c

  20. If you're planning to attend @defcon 33, and would like to quickly get up to speed on the upcoming Amass v5.0 release, then please consider registering for this workshop being hosted in the @owasp Community Room!

    #security #infosec #owasp #recon #osint #DEFCON #attacksurface

    lu.ma/hf83v61c

  21. New mass scanning activity may be the first step in another MOVEit attack.

    Hackers are actively scanning the internet for exposed MOVEit systems—hundreds of unique IPs every day—suggesting the early stages of coordinated exploitation.

    Threat intel firm GreyNoise warns this is the same pattern seen weeks before past mass attacks. Known MOVEit vulnerabilities, such as CVE-2023-34362 and CVE-2023-36934, are already being tested in the wild.

    If your MOVEit Transfer instance is online and unmonitored, you may already be on an attacker’s target list.

    Now’s the time to:
    • Patch all known MOVEit vulnerabilities
    • Limit public-facing access
    • Monitor for scan activity and open ports
    • Block IPs identified by threat intelligence feeds
    • Harden file transfer environments and deploy honeypots if needed

    Scanning isn’t random—it’s reconnaissance. Act now before scanning turns into breach.

    Read the article for details: cuinfosecurity.com/scans-probi

    #MOVEit #Cybersecurity #MassScanning #ThreatIntel #AttackSurface #LMGSecurity #Infosec #ITsecurity #databreach #CISO #DFIR #pentesting #pentest #penetrationtesting

  22. New mass scanning activity may be the first step in another MOVEit attack.

    Hackers are actively scanning the internet for exposed MOVEit systems—hundreds of unique IPs every day—suggesting the early stages of coordinated exploitation.

    Threat intel firm GreyNoise warns this is the same pattern seen weeks before past mass attacks. Known MOVEit vulnerabilities, such as CVE-2023-34362 and CVE-2023-36934, are already being tested in the wild.

    If your MOVEit Transfer instance is online and unmonitored, you may already be on an attacker’s target list.

    Now’s the time to:
    • Patch all known MOVEit vulnerabilities
    • Limit public-facing access
    • Monitor for scan activity and open ports
    • Block IPs identified by threat intelligence feeds
    • Harden file transfer environments and deploy honeypots if needed

    Scanning isn’t random—it’s reconnaissance. Act now before scanning turns into breach.

    Read the article for details: cuinfosecurity.com/scans-probi

    #MOVEit #Cybersecurity #MassScanning #ThreatIntel #AttackSurface #LMGSecurity #Infosec #ITsecurity #databreach #CISO #DFIR #pentesting #pentest #penetrationtesting

  23. Just released! Our Top Cybersecurity Control selection for Q2 2025 is Continuous Vulnerability Management (CVM).

    Why CVM? We’ve analyzed the trends, and today’s threat landscape demands more than periodic scans and reactive fixes. Attackers are exploiting new vulnerabilities within hours, sometimes minutes, of disclosure. You need a program that’s always on, and it’s also becoming a compliance necessity.

    Read the analysis on why CVM is the top control for Q2 and how to put it into action: lmgsecurity.com/why-continuous

    #Cybersecurity #ContinuousVulnerabilityManagement #VulnerabilityManagement #CVM #RiskManagement #AttackSurface #Infosec #IT #Cyberaware #CISO #Compliance #CyberRisk #Security

  24. Your digital defenses might be hiding more vulnerabilities than you think. Attackers are using automation to map every potential entry point—learn how next-gen Attack Surface Management is flipping the script on cyber threats.

    thedefendopsdiaries.com/enhanc

    #attacksurface
    #cybersecurity
    #automation
    #riskmanagement
    #infosec

  25. Your digital defenses might be hiding more vulnerabilities than you think. Attackers are using automation to map every potential entry point—learn how next-gen Attack Surface Management is flipping the script on cyber threats.

    thedefendopsdiaries.com/enhanc

    #attacksurface
    #cybersecurity
    #automation
    #riskmanagement
    #infosec

  26. It sometimes pays to run domains that serve purely as spam honeypots. Case in point: A spammer has been delivering a ConnectWise commercial remote access client application as a payload in a scam that uses the purported arrival of a US Social Security statement as its hook.

    A 🧵 ...

    #ConnectWise #malware #spam #malspam #attacksurface #SocialSecurity #SocialSecurityAdministration #SSA #usgov

  27. It sometimes pays to run domains that serve purely as spam honeypots. Case in point: A spammer has been delivering a ConnectWise commercial remote access client application as a payload in a scam that uses the purported arrival of a US Social Security statement as its hook.

    A 🧵 ...

    #ConnectWise #malware #spam #malspam #attacksurface #SocialSecurity #SocialSecurityAdministration #SSA #usgov

  28. Musk/DOGE is a widely exposed single point of failure for international security. All it takes is for a state to overcome the personal security of inexperienced barely-post-tweens to essentially access all American information. There is no oversight on how the people's data is being handled. This is the worst kind of attack surface possible.

    #infosec #doge #maga #uspol #privacy #data #attacksurface #trump

  29. Musk/DOGE is a widely exposed single point of failure for international security. All it takes is for a state to overcome the personal security of inexperienced barely-post-tweens to essentially access all American information. There is no oversight on how the people's data is being handled. This is the worst kind of attack surface possible.

    #infosec #doge #maga #uspol #privacy #data #attacksurface #trump

  30. Ideally, security schemes ought to _shrink_ the #AttackSurface.

    But shrunken attack surfaces are not very glossy. Complexity must be introduced in order to sell bolting on yet another business plan, products and services.

    Here a vulnerability and easy low-skill common point of unauthorized entry was purchased at great cost by customers thinking they were becoming safer, even as by so doing they were expanding the perimeter of their #ThreatHorizon.

    theregister.com/2025/01/09/zer

  31. Ideally, security schemes ought to _shrink_ the #AttackSurface.

    But shrunken attack surfaces are not very glossy. Complexity must be introduced in order to sell bolting on yet another business plan, products and services.

    Here a vulnerability and easy low-skill common point of unauthorized entry was purchased at great cost by customers thinking they were becoming safer, even as by so doing they were expanding the perimeter of their #ThreatHorizon.

    theregister.com/2025/01/09/zer

  32. #Microsoft plans to #force all users to use #Copilot and #Recall, two non- #AI algorithms, to keep a #database of past user actions so a user can return to them.
    Neat idea. How will they deal with the #security #AttackSurface it creates and how it makes you less #safe?

    "Absolutely! Installing #Linux is an alternative approach to avoid using Recall on your system. Linux provides a wide range of distributions (#distros) that cater to different preferences and use cases."
    Actual Microsoft Employee

    computerworld.com/article/2123

    #PopOS for me: pop.system76.com/

    Distro finder: distrochooser.de/

  33. The Amass Project received a glowing testimonial from an organization leveraging the @owasp #attacksurface mapping system:

    "For FortifyData, Amass is an invaluable tool in our arsenal for quickly and accurately determining asset footprints for cyber risk assessment. It reliably provides superior results without false positives. Further, the OAM database model provides inherent benefits beyond asset footprinting, such as identifying third parties associated with the target and nth-party detection. Working closely with the Amass team, we've watched Amass steadily enhance its capabilities. Our clients are deeply impressed with the results our platform generates using Amass data. We look forward to continuing to work with Amass and supporting its development!"

    J. Eric Smith, VP Technology Services Delivery

    Please let us know if your organization has a testimonial to share as well!

  34. Going to be in #nyc this upcoming Wednesday? Come learn with the @owasp Global Board!

    I'll be co-hosting with @redteamblueteam and doing a talk to introduce the new @amass project that builds your attack surface mapping infrastructure!

    #infosec #cyber #cybersecurity #security #recon #reconnaissance #attacksurface #attacksurfacemanagement

    meetup.com/owasp-new-york-city

  35. One of my favorite passages by Cory Doctorow ( @pluralistic ) is from "Attack Surface"; it perfectly fits so many situations and applies to so many people in these ridiculous times:

    "I have given more consideration than it is due already. Now, fuck off. Then keep fucking off. Fuck off until you come up to a gate with a sign saying 'You Can't Fuck Off Past Here'. Climb over the gate, dream the impossible dream, and keep fucking off forever."

    #coreydoctorow #attacksurface

  36. این جمله از Cory Doctorow رو امروز خوندم که در توصیف یک بنای بزرگی در شهرش نوشته بود و خیلی به دلم نشست:

    [It was] proud and beautiful without being a monument to forever wars, a symbol of resilience, not revenge.

    دوست دارم من هم چیزی بسازم که شایستهٔ چنین توصیفی باشه:

    a symbol of resilience, not revenge

    #CoryDoctorow #AttackSurface

  37. Secure your perimeter and don’t leave #risk to chance. Check out this preview of “Cosmos: Protecting the Perimeter,” and download the full report for exclusive insights into lessons from 17,000 #attacksurface exposure datapoints. bfx.social/406xEb3

    #attacksurfacemanagement #offensivesecurity