#iamsecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #iamsecurity, aggregated by home.social.
-
Truffle Security's long-term monitoring uncovered 9,300+ active AWS keys sitting in public repositories and paste sites. Over 500 were root-level credentials. Hundreds carried full admin privileges. These are open invitations to take over cloud environments, and many remain valid today.
#AWSExposedKeys #CloudSecurity #IAMSecurity #ThreatResearch
https://cyberworldops.eu/en/more-than-9300-active-aws-keys-exposed-online-hundreds-could-grant
-
CISA has added CVE-2025-61757 to the KEV catalog, confirming active exploitation against Oracle Identity Manager. The flaw enables unauthenticated RCE via a lightweight URL-based auth bypass.
Searchlight researchers show how adding ?WSDL or ;.wadl can reach protected endpoints, manipulate auth flows, escalate privileges, and pivot through core IAM systems.
Teams running affected versions should patch promptly and monitor for exploitation attempts.
💬 Join the discussion and follow TechNadu for more real-world threat insights.#Infosec #CISA #Oracle #Vulnerability #IAMSecurity #ZeroDay #ThreatResearch #SecurityOperations #CyberAwareness #PatchNow
-
CISA has added CVE-2025-61757 to the KEV catalog, confirming active exploitation against Oracle Identity Manager. The flaw enables unauthenticated RCE via a lightweight URL-based auth bypass.
Searchlight researchers show how adding ?WSDL or ;.wadl can reach protected endpoints, manipulate auth flows, escalate privileges, and pivot through core IAM systems.
Teams running affected versions should patch promptly and monitor for exploitation attempts.
💬 Join the discussion and follow TechNadu for more real-world threat insights.#Infosec #CISA #Oracle #Vulnerability #IAMSecurity #ZeroDay #ThreatResearch #SecurityOperations #CyberAwareness #PatchNow
-
CISA has added CVE-2025-61757 to the KEV catalog, confirming active exploitation against Oracle Identity Manager. The flaw enables unauthenticated RCE via a lightweight URL-based auth bypass.
Searchlight researchers show how adding ?WSDL or ;.wadl can reach protected endpoints, manipulate auth flows, escalate privileges, and pivot through core IAM systems.
Teams running affected versions should patch promptly and monitor for exploitation attempts.
💬 Join the discussion and follow TechNadu for more real-world threat insights.#Infosec #CISA #Oracle #Vulnerability #IAMSecurity #ZeroDay #ThreatResearch #SecurityOperations #CyberAwareness #PatchNow
-
These people must be qualified for The Boom Boom Room
https://youtu.be/nbVKiYTdOog?si=BhUhgzOxTgdbu21h
#YouTube #gaming #YouTubegamingn #IAmSecurity #securitysimulator #codypandajones #codypandajonesyt
-
These people must be qualified for The Boom Boom Room
https://youtu.be/nbVKiYTdOog?si=BhUhgzOxTgdbu21h
#YouTube #gaming #YouTubegamingn #IAmSecurity #securitysimulator #codypandajones #codypandajonesyt
-
These people must be qualified for The Boom Boom Room
https://youtu.be/nbVKiYTdOog?si=BhUhgzOxTgdbu21h
#YouTube #gaming #YouTubegamingn #IAmSecurity #securitysimulator #codypandajones #codypandajonesyt
-
These people must be qualified for The Boom Boom Room
https://youtu.be/nbVKiYTdOog?si=BhUhgzOxTgdbu21h
#YouTube #gaming #YouTubegamingn #IAmSecurity #securitysimulator #codypandajones #codypandajonesyt
-
These people must be qualified for The Boom Boom Room
https://youtu.be/nbVKiYTdOog?si=BhUhgzOxTgdbu21h
#YouTube #gaming #YouTubegamingn #IAmSecurity #securitysimulator #codypandajones #codypandajonesyt
-
These people must be qualified for The Boom Boom Room
https://youtu.be/nbVKiYTdOog?si=BhUhgzOxTgdbu21h
#YouTube #gaming #YouTubegamingn #IAmSecurity #securitysimulator #codypandajones #codypandajonesyt
-
These people must be qualified for The Boom Boom Room
https://youtu.be/nbVKiYTdOog?si=BhUhgzOxTgdbu21h
#YouTube #gaming #YouTubegamingn #IAmSecurity #securitysimulator #codypandajones #codypandajonesyt
-
These people must be qualified for The Boom Boom Room
https://youtu.be/nbVKiYTdOog?si=BhUhgzOxTgdbu21h
#YouTube #gaming #YouTubegamingn #IAmSecurity #securitysimulator #codypandajones #codypandajonesyt
-
Persisting Unseen: Defending against Entra ID persistence
https://kknowl.es/posts/defending-against-entra-id-persistence
-
Persisting Unseen: Defending against Entra ID persistence
https://kknowl.es/posts/defending-against-entra-id-persistence
-
Persisting Unseen: Defending against Entra ID persistence
https://kknowl.es/posts/defending-against-entra-id-persistence
-
Persisting Unseen: Defending against Entra ID persistence
https://kknowl.es/posts/defending-against-entra-id-persistence
-
Persisting Unseen: Defending against Entra ID persistence
https://kknowl.es/posts/defending-against-entra-id-persistence