Skip to content

liam-ng/fluffy-computing-machine

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

4 Commits
 
 

Repository files navigation

Lesson Learned from �Security Breaches

Cybersecurity Breaches for Payment Industry (Billtrust & Fiserv) image image image Rapid7's full technical analysis of the exploit chain for CVE-2023-34362 https://attackerkb.com/topics/mXmV0YpC3W/cve-2023-34362/rapid7-analysis?referrer=etrblog

image A strong IOC may be present in the log file C:\MOVEitTransfer\Logs\DMZ_WebApi.log

Ref 1 MOVEit Transfer Critical Vulnerability (May 2023) (CVE-2023-34362) https://community.progress.com/s/article/MOVEit-Transfer-Critical-Vulnerability-31May2023

Ref 2 Rapid7 Observed Exploitation of Critical MOVEit Transfer Vulnerability https://www.rapid7.com/blog/post/2023/06/01/rapid7-observed-exploitation-of-critical-moveit-transfer-vulnerability/

Ref 3 MOVEit Transfer Critical Vulnerability CVE-2023-34362 Rapid Response https://www.huntress.com/blog/moveit-transfer-critical-vulnerability-rapid-response

Ref 4 AttackerKB CVE-2023-34362 https://attackerkb.com/topics/mXmV0YpC3W/cve-2023-34362/rapid7-analysis?referrer=search

image

image

Appendix

Opportunities for Potential Improvement:

Interesting Tools

  • ThreagileThreat Modelling diagrams and report generator
  • PenTestGPT – an interactive Pentest tool (identification) support any LLMs

Interesting Stats

Interesting Document

NIST CSF 2.0 – A Canadian Perspective by Bradley J. Freedman https://cybersecuritylaw.ca/home/2023/10/22/nist-cybersecurity-framework-20-a-canadian-perspective NIST Cybersecurity and Privacy Reference Tool: CPRT

About

Cybersecurity Breaches for Payment Industry (Billtrust & Fiserv)

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published