bug-bounty625
facebook443
xss316
google119
rce106
microsoft66
csrf60
web355
account-takeover55
writeup50
malware43
sqli41
apple41
exploit40
ssrf35
cve34
privilege-escalation34
dos34
cloudflare29
defi28
phishing25
smart-contract-vulnerability25
access-control25
ethereum24
smart-contract24
clickjacking24
idor24
subdomain-takeover24
vulnerability-disclosure23
remote-code-execution21
auth-bypass19
lfi18
race-condition16
cloud15
authentication-bypass15
cors15
solidity15
node15
aws14
reverse-engineering13
oauth13
web-security12
sql-injection12
supply-chain12
denial-of-service11
info-disclosure11
browser11
delegatecall11
web-application-security11
vulnerability10
0
0
0
0
0
0
Assetnote discovered and demonstrated a zero-day remote code execution vulnerability affecting Mozilla's AWS network infrastructure. The article appears to be a landing page for Assetnote's security research capabilities rather than detailed technical analysis.
Mozilla
AWS
Assetnote
Searchlight Cyber
0
vulnerability
0
0
vulnerability
0
vulnerability
0
4/10
UNC6426 exploited stolen credentials from the nx npm supply chain compromise to obtain GitHub tokens, then escalated access to AWS admin privileges and exfiltrated data within 72 hours. The attack demonstrates a complete kill chain from initial package compromise through cloud credential theft to full environment breach.
supply-chain-attack
npm-package
cloud-security
aws
credential-theft
github-token
lateral-movement
unc6426
privilege-escalation
data-exfiltration
UNC6426
nx
GitHub
AWS
0
0
0
authentication