View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

RAVEN Demonstrates Elasticsearch Data Theft and Persistent Backdoor

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • RAVEN Demonstrates Elasticsearch Data Theft and Persistent Backdoor Access
    RAVEN can exfiltrate Elasticsearch data and restore deleted access mechanisms.

    • Exposed or compromised Elasticsearch clusters and Kibana environments are affected.
    • RAVEN exports selected or all non-system indices as NDJSON and can create server-side snapshots.
    • The tool creates rogue users, long-lived API keys, and Watcher tasks that recreate deleted access.
    • Testing used Docker-based Elasticsearch 7.17.22; RAVEN uses the Point-in-Time API on newer releases and Scroll before 7.10.
      πŸ“„ Source: levelblue.com Β· πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News
  • Fake Crypto AML Checkers Trick Users Into Draining Their Wallets
    Scammers are using fake crypto AML-checking sites to drain users’ wallets.

    • Crypto wallet users are targeted.
    • Fake sites impersonate legitimate anti-money-laundering services.
    • The sites trick users into approving wallet access for scammers.
    • Approved access lets attackers drain victims’ cryptocurrency.
      πŸ“Ž Coverage: securityboulevard.com Β· πŸ‘ via securityboulevard.com (discovered)

πŸ“‹ ADVISORIES

  • NIST Releases Cybersecurity Tips for Building Automation Systems
    NIST released cybersecurity guidance for building automation and control systems.

    • Commercial and federal building owners and operators are the primary audience.
    • Building Automation & Control Systems manage HVAC, lighting, access control, fire alarms and energy systems.
    • Integration with corporate networks and cloud services increases BACS exposure to cyberattacks.
    • The guidance also applies to OT environments in water, transportation, energy, manufacturing, healthcare and food/agriculture.
      πŸ“Ž Coverage: nist.gov Β· πŸ‘ via NIST Cybersecurity Insights
  • πŸ“Œ 4 | πŸ“„ Source for StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites for Malware Operations β€” blog.checkpoint.com

πŸ”“ CVEs & KEV

  • CVE-2026-52813 β€” CVSS 10.0 β€” Yet another RCE in Gogs, but it's fixed this time!

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check