243M Brazilian health records exposed by password left in website source code
Friday, December 4, 2020
Since the exposure was caused by a third-party developer, he added, it’s critical government agencies and enterprises thoroughly vet their selected partners, especially those that handle and manage consumer data. “Even if enterprises have battened down the hatches on their own security, their efforts become meaningless if they do not ensure their vendors have done the same,” he said.
Ilia Kolochenko, founder and chief executive of web security company ImmuniWeb, noted that many organizations tend to outsource software development to the cheapest providers, eventually getting the corresponding quality and security of the code.
“Cybercriminals are perfectly aware of these amazing opportunities and effortlessly harvest the long-hanging fruit,” Kolochenko said. “Worse, such incidents and consequential attacks are hard, if not impossible, to detect in a timely manner. ” Read Full Article
Threatpost: Cayman Islands Bank Records Exposed in Open Azure Blob
IT World Canada: Sophos says attacker leveraged an ‘access permission issue’