Vulnerabilities / Threats

7/24/2017
03:00 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Weather.com, Fusion Expose Data Via Google Groups Config Error

Companies that leaked data accidentally chose the sharing setting "public on the Internet," which enabled anyone on the Web to access all information contained in the messages

Major companies have publicly exposed messages containing sensitive information due to a user-controlled configuration error in Google Groups.

Researchers at RedLock Cloud Security Intelligence (CSI) discovered Google Groups belonging to hundreds of companies inadvertently exposed personally identifiable information (PII) including customer names, passwords, email and home addresses, salary compensation details, and sales pipeline data. Internal messages also exposed business strategies, which could create competitive risk if in the wrong hands, explains RedLock cofounder and CEO Varun Badhwar.

The Weather Company, the IBM-owned operator of weather.com and intellicast.com, is among the companies affected. Fusion Media Group, parent company of Gizmodo, The Onion, Jezebel, Lifehacker, and other properties made the same mistake.

"The RedLock CSI team only looked for a sample of [Google Groups] cases and found dozens," says Badhwar of this research. "Extending that, there are likely hundreds of companies affected by this misconfiguration."

Google Groups is a G Suite chat application organizations use to create and participate in email-based group chats and online forums. During the configuration process, admins can set the sharing option for "Outside this domain - access to groups" to make messages public or private.

The companies that leaked data accidentally chose the sharing setting "public on the Internet," which enabled anyone on the Web to access all information contained in their messages. RedLock advises all companies using Google Groups to ensure "private" is the sharing setting for "Outside this domain-access to groups."

RedLock's CSI team routinely checks various cloud infrastructure tools for threat vectors, and monitors publicly available data to detect misconfigurations that could cause security incidents, explains Badhwar. To date, the team has found more than 4.8 million exposed records resulting from cloud misconfiguration problems.

This is the latest example of organizations mistakenly exposing data by failing to properly configure their public cloud settings.

Shortly before RedLock announced its findings, a data leak at Dow Jones & Co. exposed millions of customers' personal information due to a configuration error in an Amazon Web Services S3 bucket. The repository had its settings configured to let any AWS authenticated user access its data, making it available to any of the one million users with a free AWS account.

Dow Jones confirmed 2.2 million people were exposed; however, Upguard, which discovered the leak, places that number around four million based on the bucket's size and composition. While Dow Jones has "no reason to believe" any of the data was stolen, its incident is one of many signs that companies are struggling to securely adopt cloud services.

Earlier this year, Upguard discovered Deep Root Analytics accidentally leaked millions of voter records from an unsecured public storage account. Exposed data included phone numbers, birthdates, home and mailing addresses, party affiliation, and self-reported racial background.

The analytics firm, working on behalf of the Republican National Committee, had set its S3 storage bucket files to public instead of private. Most records had permissions to be downloaded and files could be accessed without a password.

"The public cloud can be highly secure when configured correctly, but what we're seeing is there's an overarching learning curve when it comes to how organizations should properly secure cloud applications and public cloud infrastructure," says Badhwar.

Unfortunately, many companies are struggling with basic security. Badhwar says the RedLock CSI team found 40% of organizations have exposed a public cloud resource by incorrectly configuring sharing settings, leading to the recent series of major leaks.

"Simple misconfiguration errors -- whether in SaaS applications or cloud infrastructure -- can have potentially devastating effects," he adds, citing instances of similar mistakes at WWE and Booz Allen Hamilton.

It's important for businesses to teach employees about security practices and tools they can use to automate the process of securing applications, workloads, and systems. Until this education happens, he anticipates we will continue to see these problems.

Related Content:

Kelly Sheridan is Associate Editor at Dark Reading. She started her career in business tech journalism at Insurance & Technology and most recently reported for InformationWeek, where she covered Microsoft and business IT. Sheridan earned her BA at Villanova University. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
_geoff_p_
50%
50%
_geoff_p_,
User Rank: Author
7/25/2017 | 12:39:54 PM
User Error and Permissions Confusion Keeps Being a Problem
Great article! Between accidental oversharing from simple user errors (setting sharing to 'public') and not correctly setting permissions due to potentially confusing nameing schemes ('Any Authenticated AWS User' in Amazon S3 buckets being the latest trend) the cloud is proving that user education continues to be an incredibly important topic. Now instead of clicking a link in a phishing email and accidentally exposing a single system to compromise misconfigured clouds are exposing LARGE quantities of data without the need for external action from potential adversaries.
Hacked IV Pumps and Digital Smart Pens Can Lead to Data Breaches
Dawn Kawamoto, Associate Editor, Dark Reading,  12/4/2017
The Rising Dangers of Unsecured IoT Technology
Danielle Jackson, Chief Information Security Officer, SecureAuth,  12/4/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Managing Cyber-Risk
An online breach could have a huge impact on your organization. Here are some strategies for measuring and managing that risk.
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.