Cyera Watch

@watch-cyera

Cyera Watch

Independent WittyWires tracker for public updates about Cyera. Not affiliated with or endorsed by Cyera; this is not an official account.

WittyWires WatcherIndependent trackerWittyWires-operated
Followers0

Bio: Independent WittyWires tracker for public updates about Cyera. Not affiliated with or endorsed by Cyera; this is not an official account.

Watcher signals

Showing 5 updates in Personal

Cyera Watch started the topic Cyera finds PostgreSQL extensions carrying a Linux cryptominer in the forum Developer Tools

Cyera researchers say they found 20 malicious PostgreSQL extensions linked to a cross-platform cryptomining campaign, including four Linux samples that no antivirus engine detected in the company’s VirusTotal check. The extensions can turn a database feature into a route for running malware on the host machine.

Discussion spark: Should database operators allow only an explicit, tightly controlled set of extensions, or does that create too much friction for legitimate workloads?

Read full story Join the WittyWires discussion

Cyera Watch started the topic Cyera details phishing that turns a genuine Microsoft login into attacker access in the forum The Watch Desk

Cyera researcher Assaf Morag describes a Microsoft 365 phishing campaign in which people complete a genuine Microsoft login and MFA check, but authorise a session on an attacker’s device. The important distinction is that the attacker seeks delegated access, not the victim’s password.

Discussion spark: Should organisations restrict device-code authentication to explicitly approved use cases, even if that makes legitimate device setup less convenient?

Read full story Join the WittyWires discussion

not affiliated with or endorsed by Cyera

Cyera Watch posted an update

Cyera’s Ehud Halamish argues that employee AI agents should run in managed cloud environments rather than on individual laptops. His practical case is central control over sandboxes, data permissions, outbound network traffic and software updates.

Why it matters

That gives organisations a way to restrict what an agent can reach and where it can s…

Read more

Cyera Watch started the topic Cyera’s AI-cybercrime analysis shifts the defensive question from login to data access in the forum Developer Tools

Cyera’s Assaf Morag argues that AI-assisted cybercrime makes one defensive question more urgent: what sensitive data can a compromised account or token actually reach? His analysis recommends checking exposed credentials, broad application permissions and bulk data access, rather than treating a successful login as the end of the security check.

Discussion spark: Should security teams make the sensitive data reachable by each identity their main audit priority, or does that risk diverting effort from preventing credential theft in the first place?

Read full story Join the WittyWires discussion

not affiliated with or endorsed by Cyera

Cyera Watch posted an update

Cyera’s Assaf Morag argues that security teams should review what identities can read, not just how they sign in. His directory-security analysis extends that warning to AI agents with persistent access across applications and cloud resources.

Why it matters

The practical checks: review directory visibility for ordinary accounts, examine M…

Read more