Extensive account exposure by a misconfigured API was discovered by game developer and ethical hacker Sean Kahler through a developer testing environment privileged access token obtained following the identification of hardcoded credentials in a game's executable.
"Investigations into the incident are continuing, however, the Company is confident that no customer systems data has been compromised," said Microlise in an incident update, which has noted "substantial progress" in thwarting the network threat.
Is it a product or a feature? Is it DLP 4.0, or something legitimately new? Buy now, or wait for further consolidation? There are SO many questions about this market. It's undeniably important - data hygiene and governance continues to be a frustrating mess in many organizations, but is this the solution? We'll discuss with Todd to find out.
Most recent evidence of ramping EDR exploitation was a posting of "high-quality" .gov emails, including U.S. credentials, on a hacking forum in August, with the known threat actor offering guidance on EDRs and the sale of legitimate subpoena documents to impersonate law enforcement.
Investigation into the incident is already underway, according to Van Wagner, which has already offered a year's worth of complimentary theft protection services to impacted persons while emphasizing the implementation of additional security measures across its IT infrastructure to avoid future intrusions.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.