Open in app

Sign In

Write

Sign In

Kevin Beaumont
Kevin Beaumont

3.8K Followers

Home

About

Published in

DoublePulsar

·May 5

Capita’s “standard industry practice” 633gb open cloud storage

TechCrunch has a story today about Capita with an unsecured S3 bucket. A few people came across this last week — I saw it floating around social media and Discord amongst security researchers. Capita claim it is “information such as release notes and user guides, which are routinely published alongside…

Cybersecurity News

4 min read

Capita’s “standard industry practice” 633gb open cloud storage
Capita’s “standard industry practice” 633gb open cloud storage
Cybersecurity News

4 min read


Published in

DoublePulsar

·Apr 20

Russian hackers exfiltrated data from from Capita over a week before outage

Capita have finally admitted a data breach, but still do not think they need to disclose key details of the incident to customers, regulators, impacted parties and investors. So in this piece we shall dig into the details using open source intelligence, and prove Capita was penetrated by Black Basta…

Cybersecurity

9 min read

Russian hackers exfiltrated data from Capita over a week before outage
Russian hackers exfiltrated data from Capita over a week before outage
Cybersecurity

9 min read


Published in

DoublePulsar

·Apr 9

Black Basta ransomware group extorts Capita with stolen customer data, Capita fumble response.

There’s an interesting piece in The Times today, where the CEO of Capita declares Capita’s response to the hack “will go down as a case history for how to deal with a sophisticated cyberattack”. That’s a bold statement, so let us explore it. While that may be true on a…

Cybersecurity News

3 min read

Black Basta ransomware group extorts Capita with stolen customer data, Capita fumble response.
Black Basta ransomware group extorts Capita with stolen customer data, Capita fumble response.
Cybersecurity News

3 min read


Published in

DoublePulsar

·Mar 15

A look at CVE-2023–23415 — a Windows ICMP vulnerability + mitigations (which is not a cyber meltdown)

Yesterday Microsoft dropped a patch for a vulnerability found by @hexnomad@infosec.exchange. It’s a great vuln, in theory allowing code execution over ICMP. It also sounds really scary, as it’s a high CVSS score in Windows OS on a commonly used protocol. I’ve had a quick reverse engineer of the patch…

Cybersecurity News

3 min read

A look at CVE-2023–23415 — a Windows ICMP vulnerability + mitigations which is not a cyber meltdown
A look at CVE-2023–23415 — a Windows ICMP vulnerability + mitigations which is not a cyber meltdown
Cybersecurity News

3 min read


Published in

DoublePulsar

·Feb 9

UK government declares ransomware a “tier 1” national security threat — on par with terrorism and military crisis between states.

Those who have known me for a long time will know I’ve been banging on about ransomware for years. On here, on Twitter, in person. Here, I documented things like the emergence of Locky 7 years ago, one of the first big single endpoint ransomware incidents. I worked with the…

Ransomware

4 min read

UK government declares ransomware a “tier 1” national security threat — on par with terrorism and…
UK government declares ransomware a “tier 1” national security threat — on par with terrorism and…
Ransomware

4 min read


Published in

DoublePulsar

·Dec 8, 2022

Microsoft’s Github facilitating Ukraine government in denial of service of Russian government infrastructure

Back in February 2022, Mykhailo Fedorov — Ukraine’s Deputy Prime Minister — launched the IT Army of Ukraine: The army, which has grown to 300,000 people at peak, has been fighting a digital war with the Russian government and private enterprise. It has been incredibly successful — I have…

Cybersecurity

4 min read

Microsoft’s Github facilitating Ukraine government in denial of service of Russian government…
Microsoft’s Github facilitating Ukraine government in denial of service of Russian government…
Cybersecurity

4 min read


Published in

DoublePulsar

·Dec 3, 2022

Rackspace Cloud Office suffers destructive security breach

Thousands of small to medium size businesses are suffering as Rackspace have suffered a security breach on their Hosted Exchange service. Rackspace have now confirmed this is a ransomware incident. Yesterday, 2nd December 2022, Rackspace announced an outage to their Hosted Exchange Server: Updated followed through the day, but…

Cybersecurity

9 min read

Rackspace Cloud Office suffers destructive security breach
Rackspace Cloud Office suffers destructive security breach
Cybersecurity

9 min read


Published in

DoublePulsar

·Sep 29, 2022

ProxyNotShell— the story of the claimed zero days in Microsoft Exchange

Yesterday, cybersecurity vendor GTSC Cyber Security dropped a blog saying they had detected exploitation of a new Microsoft Exchange zero day: Warning: New attack campaign utilized a new 0-day RCE vulnerability on Microsoft Exchange Server | Blog | GTSC — Cung cấp các dịch vụ bảo mật toàn diện (gteltsc.vn) …

Cybersecurity

10 min read

ProxyNotShell— the story of the claimed zero day in Microsoft Exchange
ProxyNotShell— the story of the claimed zero day in Microsoft Exchange
Cybersecurity

10 min read


Published in

DoublePulsar

·May 29, 2022

Follina — a Microsoft Office code execution vulnerability

Two days ago, on May 27th 2022, Nao_sec identified an odd looking Word document in the wild, uploaded from an IP address in Belarus. This turned out to be a zero day vulnerability in Office and/or Windows. This caught my attention, as Defender for Endpoint missed execution: The…

Follina

9 min read

Follina — a Microsoft Office code execution vulnerability
Follina — a Microsoft Office code execution vulnerability
Follina

9 min read


Published in

DoublePulsar

·May 7, 2022

BPFDoor — an active Chinese global surveillance tool

Recently, PwC Threat Intelligence documented the existence of BPFDoor, a passive network implant for Linux they attribute to Red Menshen, a Chinese threat actor group. You can read more in PwC’s great, yearly threat intelligence brief, here. PwC plan to present their findings in June: BPFDoor is interesting…

Bpfdoor

3 min read

BPFDoor — an active Chinese global surveillance tool
BPFDoor — an active Chinese global surveillance tool
Bpfdoor

3 min read

Kevin Beaumont

Kevin Beaumont

3.8K Followers

Everything here is my personal work and opinions.

Following
  • Mitch Edwards

    Mitch Edwards

  • Mark Manson

    Mark Manson

  • Omar Santos

    Omar Santos

  • Wil Wheaton

    Wil Wheaton

  • Jang

    Jang

See all (97)

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech