Deployed within a virtual private cloud, Formal logs every request to an enterprise's data stores, such as databases containing customer information, and enforces dynamic access policies.
More than 116,000 New York residents had their driver's license numbers compromised from Geico's systems following the exploitation of its apps' pre-fill functionality and Application Programming Interface, as well as fraudulent policy purchases and claims filing, beginning November 2020, with the insurer only resolving its systems vulnerabilities by March 2021.
After infiltrating The Real World through the exploitation of a platform vulnerability, attackers proceeded to post pro-feminist and LGBTQ+ emojis, remove attachments, and issue provisional bans for users of the platform, which was previously called Hustler's University.
Threat actors who compromised Bojangles' corporate network between February and March were able to exfiltrate "certain files" containing names and other personal details, according to Bojangles.
Aside from containing full names, other personal information, and product design details, the leaked emails also included sensitive data from high-ranking U.S. military personnel, who have ordered coins, medals, and battalion emblems, according to Cybernews researchers.
Data within the unsecured database included military personnel and their supporters' full names, images, mailing addresses, locations, images, Social Security numbers, and National Insurance numbers, a report by cybersecurity researcher Jeremy Fowler published on vpnMentor showed.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.