CloudSEK
18
MENTIONS
9
EPISODES
9
PODCASTS
Search complete. 18 mentions across 9 episodes found for "CloudSEK".
Sep 8, 2026
PEEP browser backdoors, $320M Liquid exploit, BigBear beats MFA
S
1:49Sarah LaneHOST
The BigBear 2.0 phishing service compromised Microsoft 365 accounts at two hundred and fifty-eight organizations and captured more than five thousand credential records across more than 40 countries.
S
2:03Sarah LaneHOST
CloudSEK found four hundred and seventy-four completed MFA bypasses and over four thousand one hundred stolen session cookies in the services control panel.
S
2:14Sarah LaneHOST
BigBear sits between a victim and Microsoft's real login page.
S
2:18Sarah LaneHOST
It captures the authenticated session after MFA, then replays it through a residential proxy matched to the victim's location.
🔴 Sep 8's Top Cyber News NOW! - Ep 1239
S
18:56Sarah LaneSOUNDBITE_SPEAKER
2.0 phishing service compromised Microsoft 365 accounts at 258 organizations, and captured more than 5,000 credential records across more than 40 countries.
S
19:09Sarah LaneSOUNDBITE_SPEAKER
CloudSEK found 474 completed MFA bypasses, and over 4,100 stolen session cookies in the services control panel.
S
19:20Sarah LaneSOUNDBITE_SPEAKER
Big Bear sits between a victim and Microsoft's real login page.
S
19:25Sarah LaneSOUNDBITE_SPEAKER
It captures the authenticated session after MFA, then replays it through a residential proxy matched to the victim's location.
G
19:57Gerald AugerHOST
Did get it? Uh...
G
19:59Gerald AugerHOST
Um, okay.
G
20:00Gerald AugerHOST
So CloudSEK, a research company called CloudSEK actually got administrator access to the control panel.
G
20:08Gerald AugerHOST
So essentially, the good guys hacked the bad guys' platform, privileged access management, got in, and was able to basically dump what is going on with this platform.
Cybercabs, Robohobos, BigBear, Nightmare Eclipse, weChat, Flock, ASCII, Aaran Leyland - SWN #614
D
6:22Doug WhiteHOST
Yeah, I've seen that quite a bit.
D
6:25Doug WhiteHOST
Well, CloudSEK gained admin access to the control panel.
D
6:30Doug WhiteHOST
Ooh, they jumped in there and got onto Big Bear two point zero control panel and found that the service was managing forty-two virtual private server nodes, all of which were configured to target Microsoft 365.
D
6:42Doug WhiteHOST
So I guess it's an indicator of what their customers want, which is Microsoft 365.
Alleged TeamPCP hackers arrested, Cyberattack halts medical shipments, FBI dismantles Chinese hacking platforms
D
1:29David ShipleyHOST
Police allege the campaign potentially compromised more than 1,000 organizations, stole more than a half a million credentials, and exfiltrated at least 300 gigabits of data.
D
1:42David ShipleyHOST
Cybersecurity firm CloudSEK put the total credential exposure at more than 2,500 organizations.
D
1:49David ShipleyHOST
In May, TeamPCP open sourced its Shaihulud worm framework on GitHub.
D
1:54David ShipleyHOST
At the time, it looked like an attempt to muddy attribution by putting the tooling in everyone's hands.
CISA is running on empty.
D
9:35Dave BittnerHOST
CISA says exploitation can allow unauthorized access, modification, or deletion of critical data.
D
9:42Dave BittnerHOST
CloudSEK previously observed attacks targeting the vulnerability in its honeypot environment.
D
9:48Dave BittnerHOST
Exposed Oracle components could provide attackers access without valid credentials.
D
9:54Dave BittnerHOST
Both CISA and CloudSEK report active exploitation.
D
10:00Dave BittnerHOST
Taiwanese prosecutors have charged nine people over the alleged illegal export of high-end AI servers to mainland China, including individuals linked to NVIDIA and Supermicro.
D
10:13Dave BittnerHOST
Prosecutors say the case involves servers using B300 graphics processing units, which the report says are banned from sale to China.
Anthropic & OpenAI Have Changed What Moving Fast Means | Krishna M, Elevation Capital
K
0:50Krishna MehraGUEST
Sometimes raising money too quickly can be... [upbeat music]
S
0:58Siddhartha AhluwaliaHOST
Hi, this is Siddhartha Ahluwalia, your host at Neon Show and managing partner at Neon Fund, a fund that has invested in some of the best enterprise AI companies between US-India corridor, like Atomicwork, SpotDraft, CloudSEK, and many others.
S
1:11Siddhartha AhluwaliaHOST
Today I have with me Krishna Mehra.
S
1:13Siddhartha AhluwaliaHOST
Krishna, welcome to the Neon Show.
Risky Business #849 -- Trump will unleash contractors on cybercriminals
J
19:12James WilsonHOST
Well, we've learned that there's sort of a difference of opinion.
J
19:14James WilsonHOST
So the, the first article came out, was from, uh, CloudSEK and Hudson Rock.
J
19:17James WilsonHOST
Now, Hudson Rock had gotten access to a eye-wateringly large 195 terabyte file that apparently contained all these credentials that had been snapped up.
J
19:28James WilsonHOST
And this comes back to the, the March sort of era attacks around LightLLM, Trivy, et cetera, and but there, the attribution from CloudSEK and Hudson Rock was directly back to LightLLM as being the attack that netted all of these credentials.
J
19:42James WilsonHOST
The second report that's come out, though, is actually from, um, SOC Radar, who, who said, "Well, look, the, we agree that that's the credentials that have been, uh, taken in these attacks, that it all happened around that timeframe of Team PCP and the many supply chain hacks that were happening almost daily." But they checked the timestamps and said, "Look, in this data set, there is actually records of when the credential was first seen, when it was last seen, and for the vast majority of these, about 95% of the credentials, they were all first seen before the LightLLM attack." And so it appears to be actually Trivy was the, the source for these, which to me makes a lot more sense, right? Y- y- an, an exploit of Trivy, whether it is happening on a developer's laptop in a CI/CD pipeline, it's a more mature product, and it's gonna happen in places that have cloud credentials, IAM credentials, all sorts of things.
J
20:29James WilsonHOST
LightLLM never really made that much sense to me.
Security Now 1092: Restraint Abliteration
S
21:12Steve GibsonHOST
Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful," he writes, "of the entities whose access secrets were exposed.
S
21:26Steve GibsonHOST
The revelation was posted on Tuesday and Wednesday," that's la- of last week, "by security firms CloudSEK," you know, E-S-E-K, "and Hudson Rock.
S
21:35Steve GibsonHOST
CloudSEK said it found keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than twenty-five hundred organizations, and forty minutes is all it took.
S
22:00Steve GibsonHOST
The credentials were extracted during a forty-minute window in March, while the victims used un- o- obviously unknowingly, compromised versions of LiteLLM, which had been downloaded from the package's official location in the Python Package Index repository." You know, uh, PyPI.
S
22:23Steve GibsonHOST
Hudson Rock said it made the discovery after analyzing a, woo, one hundred and ninety-five terabyte file that it had obtained.
S
25:56Steve GibsonHOST
I'll clarify that in a second.
S
25:58Steve GibsonHOST
Yeah.
S
25:58Steve GibsonHOST
Um, in many cases, the researchers at CloudSEK and Hudson Rock had trouble identifying, which is a problem, the organizations, uh, the credentials belonged to.
SN 1092: Restraint Abliteration - Rotating Keys, Broken Guardrails
S
21:12Steve GibsonHOST
Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful," he writes, "of the entities whose access secrets were exposed.
S
21:26Steve GibsonHOST
The revelation was posted on Tuesday and Wednesday," that's la- of last week, "by security firms CloudSEK," you know, E-S-E-K, "and Hudson Rock.
S
21:35Steve GibsonHOST
CloudSEK said it found keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than twenty-five hundred organizations, and forty minutes is all it took.
S
22:00Steve GibsonHOST
The credentials were extracted during a forty-minute window in March, while the victims used un- o-obviously unknowingly, compromised versions of LightLLM, which had been downloaded from the package's official location in the Python package index repository." You know, uh, PyPI.
S
22:23Steve GibsonHOST
Hudson Rock said it made the discovery after analyzing a, woo, one hundred and ninety-five terabyte file that it had obtained.
S
25:56Steve GibsonHOST
I'll clarify that in a second.
S
25:58Steve GibsonHOST
Yeah.
S
25:58Steve GibsonHOST
Um, in many cases, the researchers at CloudSEK and Hudson Rock had trouble identifying, which is a problem, the organizations, uh, the credentials belonged to.