    C-Edge is a joint venture formed by Tata Consultancy Services Ltd. (TCS) and State Bank of India (SBI) to offer advanced technology solutions tailored to the needs of the financial services sector in India and other emerging markets. The company was established to harness the technical prowess of TCS and the comprehensive banking expertise of SBI, providing integrated IT solutions and services that drive digital transformation within the industry.

    One of the main focuses of C-Edge is to offer scalable and customizable software solutions to enhance efficiency, security, and customer experience...
    C-Edge Technologies Breach of Aug 2024
    Severity Score
    Significant to High


    Ransomware Attack


    C-EDGE (a joint venture between TCS and SBI), experienced a ransomware attack that disrupted India's banking ecosystem. The attack originated from a misconfigured Jenkins server at Brontoo Technology Solutions, vulnerable to CVE-2024-23897, a local file inclusion (LFI) vulnerability. Exploiting this vulnerability, the attackers gained secure shell access by reading private keys, facilitated by an open port 22.

    The RansomEXX ransomware group, known for targeting large organizations, was identified as the perpetrator. They leveraged the initial access likely obtained through an Initial Access B...
    The incident involved the exploitation of a misconfigured Jenkins server, leading to unauthorized access and subsequent disruption by the RansomEXX ransomware group.

