Denemek ALTIN - Özgür
Native Data Breach: Anatomy Of A Cloud
Enterprise IT World
|June 2019
Case study of a real-life example of a cloud-native data breach, how it evolved and how it possibly could have been avoided.
The company is a photo-sharing social media application, with over 20 million users. It stores over 1PB of user data within Amazon Web Services (AWS), and in 2018, it was the victim of a massive data breach that exposed nearly 20 million user records. This is how it happened.
Step 1: Compromising a legitimate user. Frequently, the first step in a data breach is that an attacker compromises the credentials of a legitimate user. In this incident, an attacker used a spear-phishing attack to obtain an administrative user’s credentials to the company’s environment.
Step 2: Fortifying access. After compromising a legitimate user, a hacker frequently takes steps to fortify access to the environment, independent of the compromised user. In this case, the attacker connected to the company’s cloud environment through an IP address registered in a foreign country and created API access keys with full administrative access.
Step 3: Reconnaissance. Once inside, an attacker then needs to map out what permissions are granted and what actions this role allows.
Bu hikaye Enterprise IT World dergisinin June 2019 baskısından alınmıştır.
Binlerce özenle seçilmiş premium hikayeye ve 9.000'den fazla dergi ve gazeteye erişmek için Magzter GOLD'a abone olun.
Zaten abone misiniz? Oturum aç
Enterprise IT World'den DAHA FAZLA HİKAYE
Enterprise IT World
SecurityScorecard Exposes Global ASUS Router Hijack "WrtHug" With Suspected China Links
SecurityScorecard's STRIKE threat intelligence team, working with ASUS, has uncovered Operation WrtHug- a sophisticated global espionage campaign hijacking thousands of ASUS home and SOHO routers to create covert relay nodes across Asia, the US, and Europe.
1 min
November 2025
Enterprise IT World
Armis Raises $435 Million Pre-IPO Funding, Valued at $6.1 Billion
Armis, the global leader in cyber exposure management, has secured US$435 million in pre-IPO funding, boosting its valuation to US$6.1 billion.
1 min
November 2025
Enterprise IT World
Paytm Bets on AI in Travel with Launch of 'Paytm Checkin'
Paytm (One 97 Communications Limited), India's leading digital payments and financial services company, has unveiled Paytm Checkin, an Al-powered travel app designed to transform trip planning and booking through conversational intelligence and personalization.
1 min
November 2025
Enterprise IT World
FROM AGENTIC AI TO INCLUSIVE GROWTH: IFTA UNVEILS FINTECH TRENDS 2026 AHEAD OF 10TH ANNUAL INDIA FINTECH FORUM
The 10th edition of the India FinTech Forum (IFTA) spotlights Agentic AI, embedded finance, democratization of wealth, cyber resilience, and fintech for Bharat as the key trends shaping India's financial future. The event, to be held on December 10, 2025, in Mumbai, will also honour disruptive fintech startups transforming the BFSI landscape.
4 mins
November 2025
Enterprise IT World
INDIA'S DPDP ACT: A NEW ERA FOR DATA PRIVACY AND DIGITAL TRUST
The Digital Personal Data Protection Act, 2025 sets a clear framework for consent, accountability, and governance-reshaping how businesses handle personal data in an Al-driven economy.
3 mins
November 2025
Enterprise IT World
TIRED OF SPAM CALLS? HOW THE DPDP RULES, 2025 PUT YOU BACK IN CONTROL. THE DAILY NUISANCE WE ALL KNOW
The Digital Personal Data Protection Act, 2025 sets a clear framework for consent, accountability, and governance-reshaping how businesses handle personal data in an Al-driven economy.
4 mins
November 2025
Enterprise IT World
CyberArk Launches Free TLS Certificate Scan Tools to Help Businesses Prevent Outages and Rising Labor Costs
CyberArk has unveiled two free tools -the TLS Certificate Renewal Impact Calculator and TLS Certificate Discovery Scan to help organizations prepare for a seismic shift in certificate management.
1 min
November 2025
Enterprise IT World
Consistent Infosystems to Showcase Advanced Surveillance Technologies at IFSEC India 2025
Consistent Infosystems, one of India's fastest-growing IT hardware and security technology brands, is gearing up for a strong presence at IFSEC India 2025, scheduled from 11-13 December at Pragati Maidan, New Delhi.
1 min
November 2025
Enterprise IT World
Lenovo India Surges to USD 1.2 Billion Quarterly Revenue, Fueled by Al and Digita Infrastructure Demand
Lenovo India has delivered a landmark performance in Q2 FY25/26, posting USD 1.2 billion in revenue-an impressive 23% year-on-year growth-marking one of its strongest quarters to date.
1 min
November 2025
Enterprise IT World
CyberArk's New TLS Tools Signal a Turning Point in Automation and Risk Management
As TLS certificate lifespans shrink dramatically-from 398 days today to just 47 days by 2029-automation is no longer optional; it's mission-critical for business continuity.
1 min
November 2025
Translate
Change font size
