• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Zero-day flaws in virtual event platforms provide access to personal, corporate data

You are here: Home / General Cyber Security News / Zero-day flaws in virtual event platforms provide access to personal, corporate data

At a time when most corporations have rushed to just take their gatherings virtual, numerous zero-day vulnerabilities found in function platforms frequented by the Fortune 500 offer you hackers access to individual and company info.

Scientists at Huntress have uncovered software flaws and misconfigurations in two of the top five virtual party platforms: VFairs, which counts between its customers Ford, T-Cell, IEEE and Pearson, and 6Connex. Amid the issues discovered are info disclosure or personal identifiable data leakage, direct access to databases and probable distant code execution.

“At this level, we can not predict irrespective of whether facts was actively stolen or compromised by attackers or unauthorized people,” Huntress Senior Security Researcher John Hammond wrote in a site publish following a webinar aimed at managed assistance providers that discovered the company’s investigation.

✔ Approved Seller by TheCyberSecurity.News From Our Partners
Bitdefender Internet Security 2021

Protect yourself against all threads using Bitderender. Get Bitdefender Internet Security with 68% discount from a bitdefender official seller SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


“But it surely was achievable, and these kinds of vulnerabilities could extremely well be current in a lot of other on the internet conferencing platforms,” he wrote, pointing to studies that “a digital career honest for the intelligence community hosted on the 6Connex system [last fall] exposed position seekers’ identities and social media profiles.”

Huntress claimed its conclusions to VFairs and 6Connex and both platforms have because patched the vulnerabilities.

The security organization also identified a big little and medium organization provide chain breach that disclosed a lot more than 250,000 confidential particulars on SMB mergers and acquisitions, financing and the like. “A big amount of delicate and private financing information and facts was leaked from Axial, a platform for obtaining, providing, advising and funding personal providers — all owing to neglect of basic security measures,” Hammond wrote, noting that a Twitter thread recounting the breach had been eradicated and the account banned.


Some areas of this write-up are sourced from:
www.scmagazine.com

Previous Post: «Daycare Webcam Service Exposes 12,000 User Accounts   Daycare Webcam Service Exposes 12,000 User Accounts  
Next Post: Aston Martin Partners with SentinelOne Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Recent Posts

  • Aston Martin Partners with SentinelOne
  • Zero-day flaws in virtual event platforms provide access to personal, corporate data
  • Daycare Webcam Service Exposes 12,000 User Accounts  
  • Louisiana College Cyber-Thief Sentenced
  • IBM Squashes Critical Remote Code-Execution Flaw
  • 119k Threats Per Minute Detected in 2020
  • Austin Energy warns of scammers soliciting payments in the wake of mass power outages
  • Finnish IT Giant Hit with Ransomware Cyberattack
  • 84% of CNI Orgs Experienced Cyber-Attacks in the Last Year
  • Cisco points to new tier of APT actors that behave more like cybercriminals

Copyright © TheCyberSecurity.News, All Rights Reserved.