Endpoint //

Privacy

4/6/2018
10:21 AM
50%
50%

Study Finds Petabytes of Sensitive Data Open to the Internet

New research by Digital Shadows finds more than 1.5 billion sensitive files are open to discovery on the internet.

Companies are putting their sensitive data on the internet for all the world to see. That's the conclusion of research published by security firm Digital Shadows, which found more than 1.5 billion sensitive files visible on the internet.

Misconfigured S3 buckets, NAS devices, FTP servers, and other storage and gateway systems were responsible for the vast majority of the visible files, the company says.

Visible data includes everything from patent applications to employee information, though payroll and tax return information accounted for the largest group of files available, with more than three-quarters of a million total files of these types seen. In all, Digital Shadows found more than 12 petabytes of sensitive information available to anyone bothering to look.

Third-party contractors misconfiguring systems was seen as the most significant cause of the open information. While S3 buckets have been in the news recently as a source of free data, Digital Shadows found that they only account for 7% of exposed data; technologies such as SMB (33%), rsync (28%), and FTP (26%) were responsible for the bulk of the data availability.

Digital Shadows notes that the rapidly approaching implementation of GDPR should provide companies with additional impetus to review the status of their systems and make configuration changes where necessary.

For more, read here.

Interop ITX 2018

Join Dark Reading LIVE for a two-day Cybersecurity Crash Course at Interop ITX. Learn from the industry’s most knowledgeable IT security experts. Check out the agenda here. Register with Promo Code DR200 and save $200.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2016-10739
PUBLISHED: 2019-01-21
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possib...
CVE-2019-6499
PUBLISHED: 2019-01-21
Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint database account (in viewpoint-portal\conf\server.xml) that could potentially be exploited by malicious users to compromise the affected system.
CVE-2019-6500
PUBLISHED: 2019-01-21
In Axway File Transfer Direct 2.7.1, an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request with %2e instead of '.' characters, as demonstrated by an initial /h2hdocumentation//%2e%2e/ substring.
CVE-2019-6498
PUBLISHED: 2019-01-21
GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused.
CVE-2019-6497
PUBLISHED: 2019-01-20
Hotels_Server through 2018-11-05 has SQL Injection via the controller/fetchpwd.php username parameter.