Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Attackers Use Google Cloud to Target US, UK Banks
Oldest First  |  Newest First  |  Threaded View
markgrogan
50%
50%
markgrogan,
User Rank: Strategist
1/2/2019 | 11:30:06 PM
Security practice
Are you really surfside that people would try to do this with a cloud-based storage system? Of course there are hackers everywhere who are going to try and get all of this information out of the cloud to use for their own advantage! We just need to take that information and translate it into better security practices!
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
1/3/2019 | 10:05:32 AM
Re: Security practice
Gee, what a surprise?  Hackers using the cloud, imagine that.  Give them ANY open door and they are happy to enter any way they can.  The cloud, long vaunted, is one such door.  Anybody remember the words of dear WOZniak ages ago - there is NO security in the cloud.  A lamented savant of the truth. 
DavidHamilton
50%
50%
DavidHamilton,
User Rank: Apprentice
1/10/2019 | 11:33:58 PM
Cloud storage perks and cons
Cloud storage has its pros and cons and when it is being utilized on a large scale by organisations, they ought to review the security aspects of it. The amount of data that is being uploaded online is massive and they should be noted that, that particular set of data is actually going to remain in the digital realm for good. If they are willing to grasp this concept, then only should they utilize the cloud facility, else they should really just stick to traditional data storage means.


Edge-DRsplash-10-edge-articles
7 Old IT Things Every New InfoSec Pro Should Know
Joan Goodchild, Staff Editor,  4/20/2021
News
Cloud-Native Businesses Struggle With Security
Robert Lemos, Contributing Writer,  5/6/2021
Commentary
Defending Against Web Scraping Attacks
Rob Simon, Principal Security Consultant at TrustedSec,  5/7/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: What Virtual Reality phishing attacks will look like in 2030.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-21652
PUBLISHED: 2021-05-11
A cross-site request forgery (CSRF) vulnerability in Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
CVE-2021-21653
PUBLISHED: 2021-05-11
Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier does not perform a permission check in an HTTP endpoint, allowing with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVE-2021-21654
PUBLISHED: 2021-05-11
Jenkins P4 Plugin 1.11.4 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified Perforce server using attacker-specified username and password.
CVE-2021-21655
PUBLISHED: 2021-05-11
A cross-site request forgery (CSRF) vulnerability in Jenkins P4 Plugin 1.11.4 and earlier allows attackers to connect to an attacker-specified Perforce server using attacker-specified username and password.
CVE-2021-21656
PUBLISHED: 2021-05-11
Jenkins Xcode integration Plugin 2.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.