How a Single Overprivileged Service Turned the LexisNexis Breach Into a Keys-to-the-Kingdom Moment
ID: 2ed16eac-f2a8-5122-a1c7-b305d5797b32
STIX ID: report--2ed16eac-f2a8-5122-a1c7-b305d5797b32
Feed Name: Security Boulevard
LexisNexis confirmed a breach of its AWS environment after attackers exploited the "React2Shell" vulnerability in an unpatched React frontend; the actor (FulcrumSec) claims to have exfiltrated ~3.9 million records, ~400,000 cloud user profiles and plaintext secrets from AWS Secrets Manager (including GitHub, Azure DevOps, Databricks, Salesforce and analytics credentials), and alleges an ECS task role had broad read access to secrets that amplified the breach. The report states the data was largely older (pre-2020) and that financial and active password data were not exposed, and recommends applying least-privilege IAM, secrets segmentation, short-lived credentials and monitoring to reduce similar risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
