[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fsVp-O5uKA5ityPrvv61k58ErZRNbe7q191_zikhcIeI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"5eb9bb4b-7d51-4767-9f19-44607cd23915","corporate-cloud-credentials-compromised-and-sold-on-dark-web","f64e7bfc-da0f-47d9-8969-7822eede884a","Corporate Cloud Credentials Compromised and Sold on Dark Web","A threat actor named 'vexin' is selling compromised corporate cloud access credentials from seven organizations across India, Brazil, and Colombia at discounted rates on underground markets. The breach affects companies in IT, packaging, and food sectors, demonstrating how stolen credentials become valuable commodities for cybercriminals. These compromised accounts enable threat actors to perform lateral movement within corporate networks, steal sensitive data, and establish persistent access to victim infrastructure. The incident highlights the critical importance of robust credential management and continuous monitoring of access patterns.","**Long-term improvements:**\n- regular security awareness training would help employees recognize phishing attempts and other credential harvesting techniques commonly used to obtain initial access\n\n**Detection measures:**\n- This incident could have been prevented through implementation of multi-factor authentication (MFA) on all cloud accounts, regular credential rotation policies, and continuous monitoring of login activities for anomalous behavior\n- Organizations should deploy privileged access management (PAM) solutions to control and monitor high-value accounts, implement zero-trust architecture principles, and maintain comprehensive logging of all access attempts",[12,13,14,15,16,17,18,19],"CIS Control 6","CIS Control 8","NIST AC-2","NIST AC-3","NIST IA-2","NIST AU-2","ISO 27001 A.9.1.1","ISO 27001 A.12.4.1","published","2026-03-23T18:18:25.258985+00:00","2026-03-23T18:20:02.684873+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fx.com\u002FDarkWebInformer\u002Fstatus\u002F2036124522420601168","a-threat-actor-using-the-handle-vexin-is-offering-corporate-cloud-accesses-at-a","‼️🇮🇳🇧🇷🇨🇴 A threat actor using the handle \"vexin\" is offering corporate cloud accesses at a...",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":35,"name":36,"slug":37,"description":38,"color":39},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",[]]