Tag: Breach Cloud

Attackers Exploit Public .env Files to Breach Cloud and Social Media Accounts
News

Attackers Exploit Public .env Files to Breach Cloud and Social Media Accounts

Through the use of publicly accessible environment variable files (.env) that hold login credentials for cloud and social media apps, a widespread extortion effort has compromised a number of enterprises. Throughout this effort, a number of security blunders were made, including the following: Palo Alto Networks Unit 42 stated in a report released on Thursday that they were exposing environment variables, utilizing credentials that expire quickly, and not having a least privilege design. The campaign is noteworthy for embedding its attack infrastructure inside the Amazon Web Services (AWS) environments of the compromised businesses, and then exploiting those environments as a jumping off point to search through over 230 million distinct targets for sensitive information read more ab...