[Updated] Cyber Security Incident at CloudSEK
ID: 10c5737e-3406-52b1-994b-d13e6ac20069
STIX ID: report--10c5737e-3406-52b1-994b-d13e6ac20069
Feed Name: CloudSEK Blog
CloudSEK investigated a targeted compromise where a third-party-serviced laptop returned with Vidar stealer installed; the malware exfiltrated session cookies and credential data that an attacker used to access a Jira account and internal Confluence/Jira documents. The actor published screenshots and limited customer information (names and POs for three companies) and briefly compromised a secondary Twitter account; CloudSEK reports no access to databases, source code, or production platforms and implemented improved device quarantine, EDR, access controls, and monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
