Man-in-the-cloud attack could hit leading cloud firms

Cloudy

Box, Google Drive, Dropbox and Microsoft OneDrive are all at risk from a man-in-the-cloud cyber attack that can lie completely undetected.

First reported by V3, research firm Imperva told the Black Hat security conference that some of the largest cloud-based firms on the planet are vulnerable to attacks that wouldn't even need a username or password to be carried out.

It claims that data could easily be accessed in this way and that by getting hold of a user authentication token, attackers can pilfer data and bring malware or ransomware along for the ride inside any account.

"From an attacker's point of view, there are advantages in using this technique. Malicious code is typically not left running on the machine, and the data flows out through a standard, encrypted channel. In the MITC attack, the attacker does not compromise explicit credentials," the firm stated.

Businesses at risk

The technique involves inserting a tool called Switcher into the system by using a malicious email attachment or drive-by download that utilises a flaw in browser plugins. The way it works means that users that don't regularly check their account won't notice it is there and sometimes the only option is to delete the account as the hacker key could remain in place regardless of whether the password is changed.

Businesses also need to be careful of the risks that come from this flaw and should take steps to make sure the vulnerability cannot affect their organisation, especially those that rely on malicious code detection and control communication detection to protect against attacks.

Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection