Monday, July 23, 2018

Your vendor/ Partner's security practices has a direct impact on your organization's security - 157 GB of Automaker Secrets Leaked because of insecure backup protocol used by third-party firm.




A total of seven auto companies were impacted by the data leak, including divisions of automakers Chrysler, Ford, GM, Tesla, Toyota and Volkswagen, along with automotive supplier ThyssenKrupp.

One also inadvertently leaked its own internal data, including employee scans of driver’s licenses and passports, along with invoices, contracts, and bank-routing numbers and SWIFT codes

To blame was rsync, which stands for “remote sync,” a common file transfer protocol used to mirror or backup large data sets,

Leaky rsync services are typically a result of permissions set on the rsync server. In the case of Level One, the rsync server was publicly writable.



https://threatpost.com/leaky-backup-spills-157-gb-of-automaker-secrets/134293/

No comments:

Post a Comment