Cyware Feed
enhanced-legion-credential-harvester-targets-ssh-servers-and-aws-credentials

Enhanced Legion Credential Harvester Targets SSH Servers and AWS Credentials

An updated version of the Python-based, cloud-focused hack tool called Legion—which can extract credentials from vulnerable web servers—has surfaced. The updated variant incorporates the Paramiko module to exploit SSH servers. Furthermore, it can now retrieve specific AWS credentials associated with CloudWatch, DynamoDB, and AWS Owl from Laravel web applications.

Cyware Feed
tortoiseshell-eyes-israeli-logistics-industry

Tortoiseshell Eyes Israeli Logistics Industry

Alleged Iranian nation-state hacker group Tortoiseshell performed a watering hole attack on several shipping and logistics websites in Israel to collect information about their users. Attackers stay hidden by impersonating the genuine jQuery JavaScript framework. Organizations are urged to raise awareness for watering hole attacks and always keep the systems updated.