TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Lobsters — security tag

1000 third parties could have stolen RIPE NCC session tokens - by design

mxsasha.eu via fanf · 11 hours ago · Read original ↗

ATT&CK techniques detected

3 predictions
T1190Exploit Public-Facing Application
76%
“ripe. net was fixed within approximately 10 days. anchors. atlas. ripe. net was fixed sometime before may 2025. i was not notified and discovered it independently. these issues were part of intigriti report ripencc - mmp7zvef, which paid € 1100 ( tier 1, critical ) covering both …”
T1552.004Private Keys
52%
“resources ( which i think might be read - only ), and more importantly, rpki. - adding new users, including admins, to the lir account, i. e. full access to any ripe ncc service. neither of these requires re - authentication, and neither notifies the original user or the company …”
T1649Steal or Forge Authentication Certificates
51%
“resources ( which i think might be read - only ), and more importantly, rpki. - adding new users, including admins, to the lir account, i. e. full access to any ripe ncc service. neither of these requires re - authentication, and neither notifies the original user or the company …”

Summary

Comments