Pretnje
13 direktnih pogodaka-
№ 075
Cloud IAM misconfiguration Cloud IAM misconfiguration means a user, a service account, an application or a role holds more rights than it needs. In the cloud an identity is not merely a l …pretnja · cloud
-
№ 065
Accidental Data Leak … able to the wrong people through human error, bad configuration, wrong sharing, a public repository, open cloud storage, or mail sent to the wrong address.pretnja · trust
-
№ 043
Authentication Bypass An authentication bypass means the attacker reaches a protected part of the system without logging in the ordinary way. They need not know a password. Sometimes a flaw in the logic is enough, or an unprotected endpoint, a predictable token, a misconfigured proxy, or a gap between two steps of the login.pretnja · applications
-
№ 074
Cloud storage exposure … private becomes publicly reachable through a bad configuration of a cloud service. That can be S3 buckets, blob storage, backups, logs, documents, images, data …pretnja · cloud
-
№ 064
Shadow IT Shadow IT is the use of applications, cloud services, accounts and tools without the knowledge or approval of the IT team. Employees usually do not bring them in to cause a problem but to get the work done faster: a file needs sharing, a team needs a chat, marketing needs a tool, sales needs a PDF now.pretnja · trust
-
№ 062
Shared Account Abuse Shared account abuse begins wherever several people use the same username and password. The system then no longer knows who actually did something. It knows only that a particular account was used, which for accountability is the same as knowing nothing.pretnja · trust
-
№ 051
DNS Amplification … hole internet with no need to is not merely a bad configuration but part of somebody else's problem.pretnja · availability
-
№ 050
Denial of Service / DoS … ific flaw in the application, the protocol or the configuration. A small number of specially shaped requests can consume a great deal of memory, hold connection …pretnja · availability
-
№ 073
Model theft / extraction … be direct theft of the files, the weights and the configuration, but also controlled extraction through an API, where the model is queried enough times to build …pretnja · AI / ML
-
№ 047
Path Traversal … ly into a file path, the attacker can try to read configurations, passwords, source code and system files.pretnja · applications
-
№ 020
Privilege Escalation … ies in the operating system or in software, wrong configurations, overly broad file permissions, and services running with more rights than they need. Leftover …pretnja · identity
-
№ 038
Remote Code Execution It is reached through configuration mistakes, vulnerable libraries, insecure deserialization, file upload, document parsers, memory handling or wrongly exposed …pretnja · applications
-
№ 070
SCADA/OT Attack … ches an engineering workstation and changes a PLC configuration.pretnja · physical / IoT
Tehnike
6 direktnih pogodaka-
№ 026
Configuration Abuse Configuration abuse involves exploiting misconfigured systems, services, or security controls. Attackers look for default passwords, overly broad permissions, o …tehnika · discovery
-
№ 020
Access Token Manipulation Extracting an access key from a configuration file on a compromised servertehnika · privileges
-
№ 027
Automation & Scripting … Attackers leverage system scripting interpreters, configuration management tools, and custom scripts.tehnika · discovery
-
№ 010
Exploitation … olves leveraging a flaw in software, hardware, or configuration to execute unauthorized code or bypass security controls. Vulnerabilities can exist in operating …tehnika · execution
-
№ 011
Persistence Monitoring file and configuration integrity is key to detecting persistence mechanisms.tehnika · execution
-
№ 018
Privilege Escalation Attackers exploit kernel vulnerabilities, misconfigurations, services running with excessive privileges, or weaknesses in access control mechanisms.tehnika · privileges
Odbrane
4 direktna pogotka-
№ 026
Secure Configuration Secure configuration involves applying established security baselines to all systems, services, and applications in an organization. The goal is to reduce the a …odbrana · resilience
-
№ 033
CSPM In practice you get a list of concrete misconfigurations ranked by risk — 'this bucket is public', 'this role can be assumed by anyone', 'these databases aren't …odbrana · resilience
-
№ 016
Logging & Monitoring Logging and monitoring involves the systematic recording of activities and events on systems, networks, and applications, along with regular analysis of those records to detect anomalies and security incidents.odbrana · monitoring / response
-
№ 023
Patch Management Patch management is the process of identifying, testing, and applying software updates that fix known vulnerabilities. The goal is to reduce the time window in which an attacker can exploit a known weakness.odbrana · resilience