ZeroHour

Search: “Truffle Security”

2 items

Researchers Uncover Thousands of Leaked AWS Keys

Truffle Security researchers discovered more than 9,000 publicly accessible and active AWS key pairs, creating credential exposure and account-takeover risks.

Truffle Security reported finding over 9,000 AWS key pairs that are simultaneously publicly accessible and active. Anyone retrieving such keys could potentially access the associated cloud resources without authentication. The finding underscores widespread secrets-hygiene failures in cloud environments and the risks of long-lived static credentials.

Infosecurity Magazine · 24d agoResearch

Risky Bulletin: Expired cards can be used for new transactions

Researchers show expired Visa contactless cards can be revived via NFC man-in-the-middle relay to run fraudulent transactions; roundup also covers major breaches.

University of Massachusetts Amherst researchers built an NFC man-in-the-middle rig that updates a card's expiration date in transit and relays the modified payment to POS terminals, reviving expired contactless cards; Visa terminals and the backends of all five banks studied failed to catch the manipulation. The same roundup reports Iranian hackers shut down a small UK power plant for four days, Lazarus breached South Korea's Presidential Office as part of a campaign exceeding 100 victims, and French telecom SFR suffered a breach affecting over 2.1 million customers.

Risky Business News · 24d agoResearch1