home.social

#iamsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #iamsecurity, aggregated by home.social.

fetched live
  1. Truffle Security's long-term monitoring uncovered 9,300+ active AWS keys sitting in public repositories and paste sites. Over 500 were root-level credentials. Hundreds carried full admin privileges. These are open invitations to take over cloud environments, and many remain valid today.

    #AWSExposedKeys #CloudSecurity #IAMSecurity #ThreatResearch

    cyberworldops.eu/en/more-than-

  2. CISA has added CVE-2025-61757 to the KEV catalog, confirming active exploitation against Oracle Identity Manager. The flaw enables unauthenticated RCE via a lightweight URL-based auth bypass.

    Searchlight researchers show how adding ?WSDL or ;.wadl can reach protected endpoints, manipulate auth flows, escalate privileges, and pivot through core IAM systems.

    Teams running affected versions should patch promptly and monitor for exploitation attempts.
    💬 Join the discussion and follow TechNadu for more real-world threat insights.

    #Infosec #CISA #Oracle #Vulnerability #IAMSecurity #ZeroDay #ThreatResearch #SecurityOperations #CyberAwareness #PatchNow

  3. CISA has added CVE-2025-61757 to the KEV catalog, confirming active exploitation against Oracle Identity Manager. The flaw enables unauthenticated RCE via a lightweight URL-based auth bypass.

    Searchlight researchers show how adding ?WSDL or ;.wadl can reach protected endpoints, manipulate auth flows, escalate privileges, and pivot through core IAM systems.

    Teams running affected versions should patch promptly and monitor for exploitation attempts.
    💬 Join the discussion and follow TechNadu for more real-world threat insights.

    #Infosec #CISA #Oracle #Vulnerability #IAMSecurity #ZeroDay #ThreatResearch #SecurityOperations #CyberAwareness #PatchNow

  4. CISA has added CVE-2025-61757 to the KEV catalog, confirming active exploitation against Oracle Identity Manager. The flaw enables unauthenticated RCE via a lightweight URL-based auth bypass.

    Searchlight researchers show how adding ?WSDL or ;.wadl can reach protected endpoints, manipulate auth flows, escalate privileges, and pivot through core IAM systems.

    Teams running affected versions should patch promptly and monitor for exploitation attempts.
    💬 Join the discussion and follow TechNadu for more real-world threat insights.

    #Infosec #CISA #Oracle #Vulnerability #IAMSecurity #ZeroDay #ThreatResearch #SecurityOperations #CyberAwareness #PatchNow