• About Us
  • Advertise
  • Contact Us
  • DMCA
  • Follow on Google News
Sunday, July 27, 2025
  • Login
Tribune Newsline
  • Home
  • India
    • National
    • State News
  • Business
  • Education
  • Entertainment
  • Lifestyle
    • Health & Fitness
    • Fashion & Beauty
    • Travel
    • Photography
    • Food
  • Tech
    • App News
    • Gadgets
  • Auto
  • Sports
  • World
  • Others
    • Agriculture
    • Science
    • Astrology
    • Finance/Money
    • Social Work
    • Press Release
    • Religion
No Result
View All Result
  • Home
  • India
    • National
    • State News
  • Business
  • Education
  • Entertainment
  • Lifestyle
    • Health & Fitness
    • Fashion & Beauty
    • Travel
    • Photography
    • Food
  • Tech
    • App News
    • Gadgets
  • Auto
  • Sports
  • World
  • Others
    • Agriculture
    • Science
    • Astrology
    • Finance/Money
    • Social Work
    • Press Release
    • Religion
No Result
View All Result
Tribune Newsline
No Result
View All Result
Home Business

Postmortem of Uber’s Social Engineering Hack

Tribune Newsline by Tribune Newsline
September 28, 2022
in Business
Postmortem of Uber’s Social Engineering Hack
Share on FacebookShare on Twitter

CloudSEK’s contextual AI based digital risk protection platform discovered a threat actor claiming to have compromised Uber, the American mobility service provider. Uber has confirmed the above claims and responded to the incident by stating that it is in contact with law enforcement agencies. Social engineering was employed as an initial attack vector by the threat actor.

The threat actor was able to compromise an employee’s HackerOne account to access vulnerability reports associated with Uber. To demonstrate the legitimacy of the claims, the actor has posted unauthorized messages on the HackerOne page of the company. Moreover, the attacker has also shared several screenshots of Uber’s internal environment including their GDrive, VCenter, sales metrics, Slack, and the EDR portal.

Related posts

Labmentix to Empower 1 Lakh+ IT Interns with Real-World Project Experience by End of Year

Labmentix to Empower 1 Lakh+ IT Interns with Real-World Project Experience by End of Year

July 25, 2025
Bengaluru-Based Plyneer Launches India’s First 100-Test Campaign for New Fire-Resistant Product Line

Bengaluru-Based Plyneer Launches India’s First 100-Test Campaign for New Fire-Resistant Product Line

July 24, 2025

“The Uber Hack is a classic case of failure on multiple levels where Over privilege or privilege mismanagement plays a pivotal role. Eliminating privilege escalation paths or monitoring for access changes in accounts can be initial answers for mitigation, apart from Darkweb and surface web monitoring”, says Abhinav Pandey, Cyber Threat Researcher, Cloudsek.

The actor plausibly employed social engineering techniques as an initial attack vector to compromise Uber’s infrastructure.

After attaining access to multiple credentials, the actor exploited the compromised victim’s VPN access to:

  • Pivot and escalate privileges inside the internal network
  • Scan the internal network(Intranet) for access

Subsequently, the actor gained access to an internal network(Intranet) *.corp.uber.com where the actor got access to a directory, plausibly with a name “share”, which provided the actor with numerous PowerShell scripts that contained admin credentials to the privileged access management system (Thycotic). This enabled the actor with complete access to multiple services of the entity such as Uber’s Duo, OneLogin, AWS, Gsuite Workspace, etc.

This hack had a tremendous impact on Uber starting from the Obfuscation of the application code, hindering the usability of the application, leaked credentials, and access could facilitate multiple account takeovers and leaking of sensitive and critical information of the entity. Equipping malicious actors with details required to launch sophisticated ransomware attacks, exfiltrate data, and maintain persistence, not to mention the reputational damage for Uber.

Mitigation Steps include training employees against social engineering attacks and techniques, implementing a strong password policy and enabling MFA across logins, creating specialized user groups with minimum privileges, closing unused ports, limiting file access, patching vulnerable, and exploitable endpoints, preventing private keys from being shared unencrypted in messaging systems like Slack or WhatsApp.

Singapore headquartered CloudSEK is a contextual AI (Artificial Intelligence) company, founded in 2015, by cybersecurity expert Rahul Sasi, with the aim to construct a future where intelligent machines can emulate human cognition to predict cyber threats even before they occur.

CloudSEK’s central proposition is to leverage AI to build a rapid and reliable detection, analysis, and alert system that offers swift detection across internet sources, precision analysis of threats, and prompt resolution with minimal human intervention.

CloudSEK offers the power of Cyber Crime monitoring, Brand Monitoring, Attack Surface monitoring, and Supply Chain Intelligence to give context to customers’ digital risks. CloudSEK’s single unified dashboard allows customers to triage and visualize all their digital threats in one place. CloudSEK also offers workflows and integrations to manage and remediate the identified threats.

Tags: American mobility service providerAttack Surface monitoringBrand MonitoringCloudSEKcontextual AI (Artificial Intelligence) companyCyber Crime monitoringcybersecurity expert Rahul Sasidigital risk protection platformHackerOneSupply Chain IntelligenceUberUber Hack
Previous Post

Dr. Geomcy George – Top emerging healthcare leader who is making a difference in the lives of many

Next Post

Cycle Pure launches pujaroom.com to provide a premium puja experience

Tribune Newsline

Tribune Newsline

Related Posts

Labmentix to Empower 1 Lakh+ IT Interns with Real-World Project Experience by End of Year
Business

Labmentix to Empower 1 Lakh+ IT Interns with Real-World Project Experience by End of Year

July 25, 2025
Bengaluru-Based Plyneer Launches India’s First 100-Test Campaign for New Fire-Resistant Product Line
Business

Bengaluru-Based Plyneer Launches India’s First 100-Test Campaign for New Fire-Resistant Product Line

July 24, 2025
Where Plots Breathe and Tech Makes It Easy: Manortha Builders Introduces Oxygen Park in Dholera
Business

Where Plots Breathe and Tech Makes It Easy: Manortha Builders Introduces Oxygen Park in Dholera

July 23, 2025
The Wellness Revolution Starts with AirX: How AirX Is Using Microalgae Tech to Clean India’s Indoor Air
Business

The Wellness Revolution Starts with AirX: How AirX Is Using Microalgae Tech to Clean India’s Indoor Air

July 18, 2025
Shaligram Infotech Celebrates 10 Years of Driving Digital Innovation for Global Businesses
Business

Shaligram Infotech Celebrates 10 Years of Driving Digital Innovation for Global Businesses

July 12, 2025
Shaligram Infotech, A Trusted Microsoft Partner In India, Marks 10 Years With Rebranding And Expanded Global Focus
Business

Shaligram Infotech, A Trusted Microsoft Partner In India, Marks 10 Years With Rebranding And Expanded Global Focus

July 9, 2025
Next Post
Cycle Pure launches pujaroom.com to provide a premium puja experience

Cycle Pure launches pujaroom.com to provide a premium puja experience

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

CSIR lab transfers know-how for new COVID-19 testing technique

4 years ago
Two unstoppable Indians are changing the world

Two unstoppable Indians are changing the world

2 years ago

With an innovative social mission in heart, JustAnilmission is helping rural Indians carve their footprints in the Global World

5 years ago

Meera Gandhi, CEO of Giving Back Foundation shares insights on the occasion on World Suicide Prevention Day

5 years ago
RLG Systems India Announces Launch of Eco-friendly Play Area Constructed from Tyres in association with Noida Authority

RLG Systems India Announces Launch of Eco-friendly Play Area Constructed from Tyres in association with Noida Authority

2 years ago
Adi Pocha Launches his Debut Novel "Behram's Boat" Published by Leadstart

Adi Pocha Launches his Debut Novel “Behram’s Boat” Published by Leadstart

3 years ago

BROWSE BY CATEGORIES

  • Agriculture
  • App News
  • Astrology
  • Auto
  • Business
  • Education
  • Entertainment
  • Fashion & Beauty
  • Finance/Money
  • Food
  • Gadgets
  • Health & Fitness
  • Lifestyle
  • National
  • Photography
  • Politics
  • Press Release
  • Religion
  • Science
  • Social Work
  • Sports
  • State News
  • Tech
  • Travel
  • Uncategorized
  • World

BROWSE BY TOPICS

Ace Entrepreneur actor Artificial intelligence Bengaluru Blockchain technology COVID-19 Cryptocurrency CSIR DBT Delhi Department of Biotechnology digital marketing DST Dubai Education entrepreneur Fairplay Gujarat Gurugram Hyderabad IIT Delhi Indian Institute of Technology Influencer Influencerquipo innovation Kingston Technology K Raheja Corp Homes LANXESS memory products and technology solutions model MoES Mumbai Music Industry producer Pune real estate research science Shan Se Entertainment Shantanu Bhamare Social Activist social media Surat technology solutions Urvashi Rautela

Latest News

Labmentix to Empower 1 Lakh+ IT Interns with Real-World Project Experience by End of Year

Labmentix to Empower 1 Lakh+ IT Interns with Real-World Project Experience by End of Year

July 25, 2025
Bengaluru-Based Plyneer Launches India’s First 100-Test Campaign for New Fire-Resistant Product Line

Bengaluru-Based Plyneer Launches India’s First 100-Test Campaign for New Fire-Resistant Product Line

July 24, 2025
Lotus Organics+ Launches its Shea Luxe Tinted Moisturizer

Lotus Organics+ Launches its Shea Luxe Tinted Moisturizer

July 24, 2025
Where Plots Breathe and Tech Makes It Easy: Manortha Builders Introduces Oxygen Park in Dholera

Where Plots Breathe and Tech Makes It Easy: Manortha Builders Introduces Oxygen Park in Dholera

July 23, 2025
Breathe Easy This Rainy Season with Pravek Kalp’s Ayurvedic Cough Kalp

Breathe Easy This Rainy Season with Pravek Kalp’s Ayurvedic Cough Kalp

July 23, 2025

Popular News

  • IIT Delhi launches new online platform to facilitate researchers

    61 shares
    Share 24 Tweet 15
  • Decimal Point Analytics (DPA) with 400 candidates, targets for 4000-Mega job and Career Opportunities

    55 shares
    Share 22 Tweet 14
  • Bonding well with your in-laws

    55 shares
    Share 22 Tweet 14
  • Euro Pratik set to revolutionise Indian interiors market

    54 shares
    Share 22 Tweet 14
  • Jasmin Bhasin on the Cover Page of The Lifestyle Journalist Magazine

    53 shares
    Share 21 Tweet 13
  • Young Indian stunt performer winning heart of Dubai’s people – Narsimha Chouhan (Nattu)

    53 shares
    Share 21 Tweet 13
  • Fashion Designer Seema Kalavadia honoured with Times Icons of Surat 2020-21

    53 shares
    Share 21 Tweet 13

Tribune Newsline, digital news and story platform bring you the news, articles, stories, and opinions on the latest happenings worldwide covering various sectors like nation, politics, and governance, social sector, review, foreign affairs, defence and security, latest review, lifestyle, entertainment, sports, technology, auto sectors, education, business and start-ups updates, Agriculture, Science, finance, money, food, and culture, etc.

Follow us on social media:

Latest News

  • Labmentix to Empower 1 Lakh+ IT Interns with Real-World Project Experience by End of Year
  • Bengaluru-Based Plyneer Launches India’s First 100-Test Campaign for New Fire-Resistant Product Line
  • Lotus Organics+ Launches its Shea Luxe Tinted Moisturizer
  • Where Plots Breathe and Tech Makes It Easy: Manortha Builders Introduces Oxygen Park in Dholera
  • Breathe Easy This Rainy Season with Pravek Kalp’s Ayurvedic Cough Kalp
  • India’s First Clean Supplement Brand to Put a Traffic Light on ‘Healthy’ Food

Category

July 2025
M T W T F S S
 123456
78910111213
14151617181920
21222324252627
28293031  
« Jun    

Recent News

Labmentix to Empower 1 Lakh+ IT Interns with Real-World Project Experience by End of Year

Labmentix to Empower 1 Lakh+ IT Interns with Real-World Project Experience by End of Year

July 25, 2025
Bengaluru-Based Plyneer Launches India’s First 100-Test Campaign for New Fire-Resistant Product Line

Bengaluru-Based Plyneer Launches India’s First 100-Test Campaign for New Fire-Resistant Product Line

July 24, 2025
  • About Us
  • Advertise
  • Contact Us
  • DMCA
  • Follow on Google News

© 2022 Tribune Newsline.

No Result
View All Result
  • About Us
  • Advertise
  • Contact Us
  • DMCA
  • Home
  • Privacy Policy

© 2022 Tribune Newsline.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In