Information discovered within the unsecured database included not only bills, repayment schedules, mailing lists, settings, and snapshots detailing names, credit limits, and email addresses, but also a spreadsheet with data from 56,864 individuals, which may include current and prospective clients, as well as blocked accounts.
Included in the data exposed by the server were personally identifiable information, job application forms, Security Industry Authority cards, payroll details, TrustID validated documents, and invoices from up to two decades ago, according to independent security researcher JayeLTee.
A new attack method dubbed transaction simulation spoofing has emerged as a significant threat to cryptocurrency users with its ability to let malicious actors exploit a key security feature in modern Web3 wallets.
More notable of the newly added vulnerabilities is the medium-severity BeyondTrust PRA and RS operating system command injection flaw, tracked as CVE-2024-12686, which has been leveraged by Chinese state-sponsored threat actors alongside the CVE-2024-12686 flaw to compromise the U.S. Treasury Department.
Aside from enabling rootkit installation, exploiting the flaw could also result in the establishment of persistent and unremovable malware, as well as the avoidance of Transparency, Consent, and Control security inspections, an analysis from Microsoft showed.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.