Skip to main content

Search complete. 18 mentions across 9 episodes found for "CloudSEK".

Sep 8, 2026

Sarah LaneHOST
1:49
The BigBear 2.0 phishing service compromised Microsoft 365 accounts at two hundred and fifty-eight organizations and captured more than five thousand credential records across more than 40 countries.
Sarah LaneHOST
2:03
CloudSEK found four hundred and seventy-four completed MFA bypasses and over four thousand one hundred stolen session cookies in the services control panel.
Sarah LaneHOST
2:14
BigBear sits between a victim and Microsoft's real login page.
Sarah LaneHOST
2:18
It captures the authenticated session after MFA, then replays it through a residential proxy matched to the victim's location.
Sarah LaneSOUNDBITE_SPEAKER
18:56
2.0 phishing service compromised Microsoft 365 accounts at 258 organizations, and captured more than 5,000 credential records across more than 40 countries.
Sarah LaneSOUNDBITE_SPEAKER
19:09
CloudSEK found 474 completed MFA bypasses, and over 4,100 stolen session cookies in the services control panel.
Sarah LaneSOUNDBITE_SPEAKER
19:20
Big Bear sits between a victim and Microsoft's real login page.
Sarah LaneSOUNDBITE_SPEAKER
19:25
It captures the authenticated session after MFA, then replays it through a residential proxy matched to the victim's location.
Gerald AugerHOST
19:57
Did get it? Uh...
Gerald AugerHOST
19:59
Um, okay.
Gerald AugerHOST
20:00
So CloudSEK, a research company called CloudSEK actually got administrator access to the control panel.
Gerald AugerHOST
20:08
So essentially, the good guys hacked the bad guys' platform, privileged access management, got in, and was able to basically dump what is going on with this platform.
Doug WhiteHOST
6:22
Yeah, I've seen that quite a bit.
Doug WhiteHOST
6:25
Well, CloudSEK gained admin access to the control panel.
Doug WhiteHOST
6:30
Ooh, they jumped in there and got onto Big Bear two point zero control panel and found that the service was managing forty-two virtual private server nodes, all of which were configured to target Microsoft 365.
Doug WhiteHOST
6:42
So I guess it's an indicator of what their customers want, which is Microsoft 365.
David ShipleyHOST
1:29
Police allege the campaign potentially compromised more than 1,000 organizations, stole more than a half a million credentials, and exfiltrated at least 300 gigabits of data.
David ShipleyHOST
1:42
Cybersecurity firm CloudSEK put the total credential exposure at more than 2,500 organizations.
David ShipleyHOST
1:49
In May, TeamPCP open sourced its Shaihulud worm framework on GitHub.
David ShipleyHOST
1:54
At the time, it looked like an attempt to muddy attribution by putting the tooling in everyone's hands.
Dave BittnerHOST
9:35
CISA says exploitation can allow unauthorized access, modification, or deletion of critical data.
Dave BittnerHOST
9:42
CloudSEK previously observed attacks targeting the vulnerability in its honeypot environment.
Dave BittnerHOST
9:48
Exposed Oracle components could provide attackers access without valid credentials.
Dave BittnerHOST
9:54
Both CISA and CloudSEK report active exploitation.
Dave BittnerHOST
10:00
Taiwanese prosecutors have charged nine people over the alleged illegal export of high-end AI servers to mainland China, including individuals linked to NVIDIA and Supermicro.
Dave BittnerHOST
10:13
Prosecutors say the case involves servers using B300 graphics processing units, which the report says are banned from sale to China.
Krishna MehraGUEST
0:50
Sometimes raising money too quickly can be... [upbeat music]
Siddhartha AhluwaliaHOST
0:58
Hi, this is Siddhartha Ahluwalia, your host at Neon Show and managing partner at Neon Fund, a fund that has invested in some of the best enterprise AI companies between US-India corridor, like Atomicwork, SpotDraft, CloudSEK, and many others.
Siddhartha AhluwaliaHOST
1:11
Today I have with me Krishna Mehra.
Siddhartha AhluwaliaHOST
1:13
Krishna, welcome to the Neon Show.
James WilsonHOST
19:12
Well, we've learned that there's sort of a difference of opinion.
James WilsonHOST
19:14
So the, the first article came out, was from, uh, CloudSEK and Hudson Rock.
James WilsonHOST
19:17
Now, Hudson Rock had gotten access to a eye-wateringly large 195 terabyte file that apparently contained all these credentials that had been snapped up.
James WilsonHOST
19:28
And this comes back to the, the March sort of era attacks around LightLLM, Trivy, et cetera, and but there, the attribution from CloudSEK and Hudson Rock was directly back to LightLLM as being the attack that netted all of these credentials.
James WilsonHOST
19:42
The second report that's come out, though, is actually from, um, SOC Radar, who, who said, "Well, look, the, we agree that that's the credentials that have been, uh, taken in these attacks, that it all happened around that timeframe of Team PCP and the many supply chain hacks that were happening almost daily." But they checked the timestamps and said, "Look, in this data set, there is actually records of when the credential was first seen, when it was last seen, and for the vast majority of these, about 95% of the credentials, they were all first seen before the LightLLM attack." And so it appears to be actually Trivy was the, the source for these, which to me makes a lot more sense, right? Y- y- an, an exploit of Trivy, whether it is happening on a developer's laptop in a CI/CD pipeline, it's a more mature product, and it's gonna happen in places that have cloud credentials, IAM credentials, all sorts of things.
James WilsonHOST
20:29
LightLLM never really made that much sense to me.
Steve GibsonHOST
21:12
Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful," he writes, "of the entities whose access secrets were exposed.
Steve GibsonHOST
21:26
The revelation was posted on Tuesday and Wednesday," that's la- of last week, "by security firms CloudSEK," you know, E-S-E-K, "and Hudson Rock.
Steve GibsonHOST
21:35
CloudSEK said it found keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than twenty-five hundred organizations, and forty minutes is all it took.
Steve GibsonHOST
22:00
The credentials were extracted during a forty-minute window in March, while the victims used un- o- obviously unknowingly, compromised versions of LiteLLM, which had been downloaded from the package's official location in the Python Package Index repository." You know, uh, PyPI.
Steve GibsonHOST
22:23
Hudson Rock said it made the discovery after analyzing a, woo, one hundred and ninety-five terabyte file that it had obtained.
Steve GibsonHOST
25:56
I'll clarify that in a second.
Steve GibsonHOST
25:58
Yeah.
Steve GibsonHOST
25:58
Um, in many cases, the researchers at CloudSEK and Hudson Rock had trouble identifying, which is a problem, the organizations, uh, the credentials belonged to.
Steve GibsonHOST
21:12
Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful," he writes, "of the entities whose access secrets were exposed.
Steve GibsonHOST
21:26
The revelation was posted on Tuesday and Wednesday," that's la- of last week, "by security firms CloudSEK," you know, E-S-E-K, "and Hudson Rock.
Steve GibsonHOST
21:35
CloudSEK said it found keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than twenty-five hundred organizations, and forty minutes is all it took.
Steve GibsonHOST
22:00
The credentials were extracted during a forty-minute window in March, while the victims used un- o-obviously unknowingly, compromised versions of LightLLM, which had been downloaded from the package's official location in the Python package index repository." You know, uh, PyPI.
Steve GibsonHOST
22:23
Hudson Rock said it made the discovery after analyzing a, woo, one hundred and ninety-five terabyte file that it had obtained.
Steve GibsonHOST
25:56
I'll clarify that in a second.
Steve GibsonHOST
25:58
Yeah.
Steve GibsonHOST
25:58
Um, in many cases, the researchers at CloudSEK and Hudson Rock had trouble identifying, which is a problem, the organizations, uh, the credentials belonged to.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.