Temporary Advertisements:
Ad
Ad
Ad
JumpCloud discloses breach by state-backed APT hacking group
by Sheriff - Monday July 17, 2023 at 02:53 PM
#1
US-based enterprise software firm JumpCloud says a state-backed hacking group breached its systems almost one month ago as part of a highly targeted attack focused on a limited set of customers.

The company discovered the incident on June 27, one week after the attackers breached its systems via a spear-phishing attack.
While JumpCloud did not find evidence that its customers were impacted at the time, the company decided to rotate credentials and rebuild compromised infrastructure.

On July 5, JumpCloud discovered "unusual activity in the commands framework for a small set of customers" while investigating the attack and analyzing logs for signs of malicious activity in collaboration with IR partners and law enforcement.

The same day, the company force-rotates all admin API keys to protect customers' organizations and notifies them to generate new keys.
"Continued analysis uncovered the attack vector: data injection into our commands framework. The analysis also confirmed suspicions that the attack was extremely targeted and limited to specific customers," JumpCloud CISO Bob Phan said.

"These are sophisticated and persistent adversaries with advanced capabilities. Our strongest line of defense is through information sharing and collaboration."
Together with the incident details shared in the advisory JumpCloud also released indicators of compromise (IOCs) to allow partners to secure their networks from similar attacks from the same threat group.

JumpCloud has yet to provide any information on the number of customers impacted by the attack and hasn't linked the APT group behind the breach with a specific state.
"We will continue to enhance our own security measures to protect our customers from future threats and will work closely with our government and industry partners to share information related to this threat," Phan said.

In January, JumpCloud also investigated the potential impact of a CircleCI security incident on its customers.
Founded in 2013 and headquartered in Louisville, Colorado, the JumpCloud directory-as-a-service platform provides single sign-on and multi-factor authentication services to over 180,000 organizations in more than 160 countries.

https://www.bleepingcomputer.com/news/se...ing-group/

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Scamming
Reply
#2
their mfa didnt work anyways it was dogwater the emp they comped prob didnt even use it himself xd
Reply
#3
dang!!!!!!!!
Hidden Content
You must register or login to view this content.
Reply
#4
(Jul 17, 2023, 02:53 PM)TIA Wrote: US-based enterprise software firm JumpCloud says a state-backed hacking group breached its systems almost one month ago as part of a highly targeted attack focused on a limited set of customers.

The company discovered the incident on June 27, one week after the attackers breached its systems via a spear-phishing attack.
While JumpCloud did not find evidence that its customers were impacted at the time, the company decided to rotate credentials and rebuild compromised infrastructure.

On July 5, JumpCloud discovered "unusual activity in the commands framework for a small set of customers" while investigating the attack and analyzing logs for signs of malicious activity in collaboration with IR partners and law enforcement.

The same day, the company force-rotates all admin API keys to protect customers' organizations and notifies them to generate new keys.
"Continued analysis uncovered the attack vector: data injection into our commands framework. The analysis also confirmed suspicions that the attack was extremely targeted and limited to specific customers," JumpCloud CISO Bob Phan said.

"These are sophisticated and persistent adversaries with advanced capabilities. Our strongest line of defense is through information sharing and collaboration."
Together with the incident details shared in the advisory JumpCloud also released indicators of compromise (IOCs) to allow partners to secure their networks from similar attacks from the same threat group.

JumpCloud has yet to provide any information on the number of customers impacted by the attack and hasn't linked the APT group behind the breach with a specific state.
"We will continue to enhance our own security measures to protect our customers from future threats and will work closely with our government and industry partners to share information related to this threat," Phan said.

In January, JumpCloud also investigated the potential impact of a CircleCI security incident on its customers.
Founded in 2013 and headquartered in Louisville, Colorado, the JumpCloud directory-as-a-service platform provides single sign-on and multi-factor authentication services to over 180,000 organizations in more than 160 countries.

https://www.bleepingcomputer.com/news/se...ing-group/

TRUSTED BY OVER 200K ORGANIZATIONS WORLDWIDE
while on the article it's 180,000 organizations
Dodgy

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Sale of public leaks + attempted scam and manipulation. Shame. | https://breached.hn/Forum-Ban-Appeals if you feel this is incorrect.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Buy THC Vape Hash/Weed in/ Dubai +971504072228 jestdnks 0 152 Yesterday, 07:28 AM
Last Post: jestdnks
  THC Vape For Sale in Dubai Whatsapp +971504072228 jestdnks 0 117 Yesterday, 07:25 AM
Last Post: jestdnks
  Buy THC Vape Juice in Dubai +971504072228 jestdnks 0 112 Yesterday, 07:23 AM
Last Post: jestdnks
Rainbow 🌐 Profesyonel Database Solutions & Data Extraction Services zeynus22 0 168 Oct 02, 2026, 01:15 PM
Last Post: zeynus22
  epsilon hacker "Chat Noir" arrested for FREE SAS breach Angel_Batista 26 5,808 Oct 02, 2026, 01:31 AM
Last Post: xxasddsaxx

Forum Jump:


 Users browsing this forum: