Postmortem of Uber's Social Engineering Hack : vimarsana.com

Postmortem of Uber's Social Engineering Hack

New Delhi [India], September 27 (ANI/GPRC): CloudSEK's contextual AI based digital risk protection platform discovered a threat actor claiming to have compromised Uber, the American mobility service provider. Uber has confirmed the above claims and responded to the incident by stating that it is in contact with law enforcement agencies. Social engineering was employed as an initial attack vector by the threat actor. The threat actor was able to compromise an employee's HackerOne account to access vulnerability reports associated with Uber. To demonstrate the legitimacy of the claims, the actor has posted unauthorized messages on the HackerOne page of the company. Moreover, the attacker has also shared several screenshots of Uber's internal environment including their GDrive, VCenter, sales metrics, Slack, and the EDR portal. "The Uber Hack is a classic case of failure on multiple levels where Over privilege or privilege mismanagement plays a pivotal role. Eliminating privilege escalation paths or monitoring for access changes in accounts can be initial answers for mitigation, apart from Darkweb and surface web monitoring", says Abhinav Pandey, Cyber Threat Researcher, Cloudsek. The actor plausibly employed social engineering techniques as an initial attack vector to compromise Uber's infrastructure. After attaining access to multiple credentials, the actor exploited the compromised victim's VPN access to: Pivot and escalate privileges inside the internal network Scan the internal network(Intranet) for access Subsequently, the actor gained access to an internal network(Intranet) *.corp.uber.com where the actor got access to a directory, plausibly with a name "share", which provided the actor with numerous PowerShell scripts that contained admin credentials to the privileged access management system (Thycotic). This enabled the actor with complete access to multiple services of the entity such as Uber's Duo, OneLogin, AWS, Gsuite Workspace, etc. This hack had a tremendous impact on Uber starting from the Obfuscation of the application code, hindering the usability of the application, leaked credentials, and access could facilitate multiple account takeovers and leaking of sensitive and critical information of the entity. Equipping malicious actors with details required to launch sophisticated ransomware attacks, exfiltrate data, and maintain persistence, not to mention the reputational damage for Uber. Mitigation Steps include training employees against social engineering attacks and techniques, implementing a strong password policy and enabling MFA across logins, creating specialized user groups with minimum privileges, closing unused ports, limiting file access, patching vulnerable, and exploitable endpoints, preventing private keys from being shared unencrypted in messaging systems like Slack or WhatsApp. Singapore headquartered CloudSEK is a contextual AI (Artificial Intelligence) company, founded in 2015, by cybersecurity expert Rahul Sasi, with the aim to construct a future where intelligent machines can emulate human cognition to predict cyber threats even before they occur. CloudSEK's central proposition is to leverage AI to build a rapid and reliable detection, analysis, and alert system that offers swift detection across internet sources, precision analysis of threats, and prompt resolution with minimal human intervention. CloudSEK offers the power of Cyber Crime monitoring, Brand Monitoring, Attack Surface monitoring, and Supply Chain Intelligence to give context to customers' digital risks. CloudSEK's single unified dashboard allows customers to triage and visualize all their digital threats in one place. CloudSEK also offers workflows and integrations to manage and remediate the identified threats. Singapore headquartered CloudSEK is a contextual AI (Artificial Intelligence) company, founded in 2015, by cybersecurity expert Rahul Sasi, with the aim to construct a future where intelligent machines can emulate human cognition to predict cyber threats even before they occur. CloudSEK's central proposition is to leverage AI to build a rapid and reliable detection, analysis, and alert system that offers swift detection across internet sources, precision analysis of threats, and prompt resolution with minimal human intervention. CloudSEK offers the power of Cyber Crime monitoring, Brand Monitoring, Attack Surface monitoring, and Supply Chain Intelligence to give context to customers' digital risks. CloudSEK's single unified dashboard allows customers to triage and visualize all their digital threats in one place. CloudSEK also offers workflows and integrations to manage and remediate the identified threats. This story has been provided by GPRC. ANI will not be responsible in any way for the content in this article. (ANI/GPRC)

Related Keywords

United States , New Delhi , Delhi , India , Singapore , American , Abhinav Pandey , Rahul Sasi , , Uber Hack , Cyber Threat Researcher , Gsuite Workspace , Artificial Intelligence , Cyber Crime , Brand Monitoring , Attack Surface , Supply Chain Intelligence , New Delhi India , Eptember 27 Ani Gprc Cloudsek 39s Contextual Ai Based Digital Risk Protection Platform Discovereda Threat Actor Claiming To Have Compromised Uber , He American Mobility Service Provider Uber Has Confirmed The Above Claims And Responded To Incident By Stating That It Is In Contact With Law Enforcement Agencies Social Engineering Was Employed As An Initial Attack Vector Threat Actor Able Compromise Employee 39s Hackerone Account Access Vulnerability Reports Associated Demonstrate Legitimacy Of , He Actor Has Posted Unauthorized Messages On The Hackerone Page Of Company Moreover , He Attacker Has Also Shared Several Screenshots Of Uber 39s Internal Environment Including Their Gdrive , Center , Sales Metrics , Black , Nd The Edr Portal Quot Uber Hack Isa Classic Case Of Failure On Multiple Levels Where Over Privilege Or Mismanagement Playsa Pivotal Role Eliminating Escalation Paths Monitoring For Access Changes In Accounts Can Be Initial Answers Mitigation , Part From Darkweb And Surface Web Monitoring Quot , Ays Abhinav Pandey , Loudsek The Actor Plausibly Employed Social Engineering Techniques As An Initial Attack Vector To Compromise Uber 39s Infrastructure After Attaining Access Multiple Credentials , He Actor Exploited The Compromised Victim 39s Vpn Access To Pivot And Escalate Privileges Inside Internal Network Scan Intranet For Subsequently , He Actor Gained Access To An Internal Network Intranet Corp Uber Com Where The Got Toa Directory , Lausibly Witha Name Quot Share , Hich Provided The Actor With Numerous Powershell Scripts That Contained Admin Credentials To Privileged Access Management System Thycotic This Enabled Complete Multiple Services Of Entity Such As Uber 39s Duo , Onelogin , Laws , Tc This Hack Hada Tremendous Impact On Uber Starting From The Obfuscation Of Application Code , Indering The Usability Of Application , Leaked Credentials , Nd Access Could Facilitate Multiple Account Takeovers And Leaking Of Sensitive Critical Information The Entity Equipping Malicious Actors With Details Required To Launch Sophisticated Ransomware Attacks , Exfiltrate Data , Nd Maintain Persistence , Ot To Mention The Reputational Damage For Uber Mitigation Steps Include Training Employees Against Social Engineering Attacks And Techniques , Mplementinga Strong Password Policy And Enabling Mfa Across Logins , Reating Specialized User Groups With Minimum Privileges , Losing Unused Ports , Imiting File Access , Atching Vulnerable , Nd Exploitable Endpoints , Reventing Private Keys From Being Shared Unencrypted In Messaging Systems Like Slack Or Whatsapp Singapore Headquartered Cloudsek Isa Contextual Ai Artificial Intelligence Company , Ounded In 2015 , Y Cybersecurity Expert Rahul Sasi , Ith The Aim To Constructa Future Where Intelligent Machines Can Emulate Human Cognition Predict Cyber Threats Even Before They Occur Cloudsek 39s Central Proposition Is Leverage Ai Builda Rapid And Reliable Detection , Analysis , Nd Alert System That Offers Swift Detection Across Internet Sources , Recision Analysis Of Threats , Nd Prompt Resolution With Minimal Human Intervention Cloudsek Offers The Power Of Cyber Crime Monitoring , Attack Surface Monitoring , Nd Supply Chain Intelligence To Give Context Customers 39 Digital Risks Cloudsek 39s Single Unified Dashboard Allows Triage And Visualize All Their Threats In One Place Also Offers Workflows Integrations Manage Remediate The Identified Singapore Headquartered Isa Contextual Ai Artificial Company , Nd Supply Chain Intelligence To Give Context Customers 39 Digital Risks Cloudsek 39s Single Unified Dashboard Allows Triage And Visualize All Their Threats In One Place Also Offers Workflows Integrations Manage Remediate The Identified This Story Has Been Provided By Gprc Ani Will Not Be Responsible Any Way For Content Article ,

© 2025 Vimarsana