Resecurity
-
Foreign intruders accessed Kansas City weapons plant IT via SharePoint flaws, source says
A source familiar with an August response says a foreign actor exploited unpatched Microsoft SharePoint flaws to access the Kansas City National Security Campus IT network. Investigations are ongoing, attribution is disputed between Chinese-linked groups and possible Russian actors, and experts warn the incident highlights gaps between IT and operational technology security.
-
Public appsettings.json leak exposes Azure AD credentials, enabling potential cloud access
Researchers from Resecurity’s HUNTER team warn that a publicly accessible appsettings.json file leaked Azure AD credentials (ClientId and ClientSecret), potentially enabling attackers to authenticate via OAuth 2.0 and access an organization’s Azure cloud resources; the incident underscores the ongoing risk of cloud-secret exposure and the need for strong secret-management practices.
-
Cybersecurity Firm Exposes Ransomware Infrastructure, Protects Victims
Cybersecurity firm Resecurity has successfully infiltrated and dismantled the infrastructure of the BlackLock ransomware gang, providing critical alerts to victims ahead of planned data leaks.



