Infosys McCamish Systems Third-Party Breach: Possible Attack Vectors and Infrastructure
ID: 938fc40d-8529-5d3d-b06f-c9226aa8dd0b
STIX ID: report--938fc40d-8529-5d3d-b06f-c9226aa8dd0b
Feed Name: SecurityScorecard Blog
SecurityScorecard investigated a November 2023 incident in which LockBit claimed a breach of Infosys McCamish Systems (IMS). The analysis identified 23 potentially compromised IMS credentials, open SSH ports across 16 Infosys BPM IPs, and NetFlow evidence of repeated communications with known-malicious and anonymizing infrastructure (including a frequently communicating IP 45.115.113.94 linked to a compromised MikroTik router), indicating plausible attacker access vectors and emphasizing the need for stronger third-party vendor security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
