Pretnje
6 direktnih pogodaka-
№ 075
Cloud IAM misconfiguration Cloud IAM misconfiguration means a user, a service account, an application or a role holds more rights than it needs. In the cloud an identity is not merely a l …pretnja · cloud
-
№ 065
Accidental Data Leak An accidental data leak is not an attack in the classic sense, but the consequences can look the same. Data becomes available to the wrong people through human error, bad configuration, wrong sharing, a public repository, open cloud storage, or mail sent to the wrong address.pretnja · trust
-
№ 043
Authentication Bypass An authentication bypass means the attacker reaches a protected part of the system without logging in the ordinary way. They need not know a password. Sometimes a flaw in the logic is enough, or an unprotected endpoint, a predictable token, a misconfigured proxy, or a gap between two steps of the login.pretnja · applications
-
№ 074
Cloud storage exposure Cloud storage exposure arises when data that ought to be private becomes publicly reachable through a bad configuration of a cloud service. That can be S3 buckets, blob storage, backups, logs, documents, images, database exports or configuration files.pretnja · cloud
-
№ 064
Shadow IT Shadow IT is the use of applications, cloud services, accounts and tools without the knowledge or approval of the IT team. Employees usually do not bring them in to cause a problem but to get the work done faster: a file needs sharing, a team needs a chat, marketing needs a tool, sales needs a PDF now.pretnja · trust
-
№ 062
Shared Account Abuse Shared account abuse begins wherever several people use the same username and password. The system then no longer knows who actually did something. It knows only that a particular account was used, which for accountability is the same as knowing nothing.pretnja · trust
Tehnike
2 direktna pogotka-
№ 026
Configuration Abuse Misconfiguration is one of the most common causes of security breaches. Unlike code vulnerabilities, configuration errors are often environment-specific and dif …tehnika · discovery
-
№ 018
Privilege Escalation Attackers exploit kernel vulnerabilities, misconfigurations, services running with excessive privileges, or weaknesses in access control mechanisms.tehnika · privileges
Odbrane
2 direktna pogotka-
№ 033
CSPM In practice you get a list of concrete misconfigurations ranked by risk — 'this bucket is public', 'this role can be assumed by anyone', 'these databases aren't …odbrana · resilience
-
№ 023
Patch Management Patch management is the process of identifying, testing, and applying software updates that fix known vulnerabilities. The goal is to reduce the time window in which an attacker can exploit a known weakness.odbrana · resilience