
🚨 FulcrumSec Claims LexisNexis AWS Breach: 2.04GB Stolen After React2Shell Exploit FulcrumSec alleges it exploited an unpatched React2Shell RCE (CVE-2024-4358) to compromise an AWS ECS task role with broad read permissions and then access Redshift, multiple VPC databases, and AWS Secrets Manager—claiming ~3.9M records, cloud user profiles (including .gov accounts), enterprise customer data, and plaintext secrets/credentials. The incident highlights cloud IAM over-privilege + weak credential hygiene (e.g., “Lexis1234”) as a fast path from a web-app bug to full cloud data warehouse exposure. 🎯 Target: Global/Legal Data & Government-Adjacent Users #️⃣ Category: #DataBreach #CyberCrime #Vulnerability #TargetedAttacks 🔗 URL: https://cyberpress.org/lexisnexis-data-breach/
Post summary
FulcrumSec claims that the unpatched CVE‑2024‑4358 React2Shell RCE was exploited to breach LexisNexis AWS, resulting in a significant data breach and the theft of millions of records, yet no PoC, exploit code, or patch details are provided.
