Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
200M Records of US Citizens Leaked in Unprotected Database
Oldest First  |  Newest First  |  Threaded View
sakaarij2
50%
50%
sakaarij2,
User Rank: Apprentice
3/22/2020 | 12:39:04 AM
Comment on 200M Records of US Citizens Leaked in Unprotected Database
That was a very good article Kelly, I am not that technical but I see Data is the new gold as we are advancing in AI data is going to be the main target for hackers, I also learnt from this article single point of failure bound to happen in my opinion Blockchain technology will help to secure database. Thank you for sharing the wonderful article love to read more article and gain knowledge thank you again Kelly   
tdsan
50%
50%
tdsan,
User Rank: Ninja
3/26/2020 | 12:05:50 PM
Re: Comment on 200M Records of US Citizens Leaked in Unprotected Database
Wow, another breach where human error and misconfiguration played a role in 800 million records found on the Internet. The data privacy and the controls that were once supposed to be implemented are out of the door. AWS, Azure and GCP have put in measures to help with user error and oversight but it seems that it continues to happen. I am looking for GDPR or FTC to take a front seat to address this issue (sanctions and injunctions) but it seems that this will get brushed under the rug for someone's incompetence work. This is almost laughable but the sheer detail of informaiton found on the web, that had been monitoried months by a security team over the internet is sad. Someone's job or jail time needs to be involved because this PII infromation could be used for nefarious purposes that could affect the lives of citizens across the US (credit monitoring from Experian is not going to fix this, lol).

AWS S3 Bucket



I am trying to figure out why couldn't they do that on the various S3 buckets that were found in the public domain, just curious or someone from the inside set it up to make them look bad (disgruntled employee). I dont' put anything past emotional turmoil.

T

 


COVID-19: Latest Security News & Commentary
Dark Reading Staff 6/1/2020
Stay-at-Home Orders Coincide With Massive DNS Surge
Robert Lemos, Contributing Writer,  5/27/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Well I dont run on MacOS, so I need to take extra precautions"
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-18623
PUBLISHED: 2020-06-02
Grafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
CVE-2018-18624
PUBLISHED: 2020-06-02
Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
CVE-2018-18625
PUBLISHED: 2020-06-02
Grafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
CVE-2019-11843
PUBLISHED: 2020-06-02
The MailPoet plugin before 3.23.2 for WordPress allows remote attackers to inject arbitrary web script or HTML using extra parameters in the URL (Reflective Server-Side XSS).
CVE-2020-5410
PUBLISHED: 2020-06-02
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL t...