Infiltration of Byte Federal's systems exposed individuals' full names, birthdates, physical addresses, email addresses, phone numbers, Social Security numbers, government-issued IDs, photos, and transaction activity, according to the firm's data breach notice, which emphasized that there has been no indication suggesting misuse of such data.
Aside from disrupting servers through a deluge of requests to "debug/pprof/heap" and other endpoints, attackers could also exploit Prometheus' "metrics" endpoint to obtain information from internal API endpoints, Docker registries, subdomains, and images that could be leveraged for reconnaissance efforts.
Conducted across six countries, the survey identifies risky behaviors such as personal device usage, poor password practices, and unauthorized access to sensitive data, which undermine workplace security.
The product, which was announced ahead of the AWS re:Invent 2024 event, leverages Amazon S3 Versioning to enable rapid, scalable recovery of data at specific points in time, simplifying processes that are typically resource-intensive and error-prone.
Such newly secured funds would be allocated toward bolstering NHI protections, noted Astrix Security, which touted its agentless platform's ability to discover and consolidate NHIs that helps reduce the risk of various cyber threats, including data breaches and supply chain compromise.
Investigation into the incident, which was only finalized earlier last month, revealed that Money Message was able to exfiltrate individuals' demographic details, medical and health insurance information, financial data, Social Security and driver's license numbers, and other personal and health details.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.