Misconfigured server exposed half of Brazilian taxpayer ID numbers: report

A database containing personally identifying information of 120 million Brazilian citizens and residents was accessible on the open web for some time, according to a report published Tuesday by cybersecurity company InfoArmor. The records reportedly contained the Cadastro de Pessoas Físicas (CPF) — a counterpart to Social Security numbers — of more than half of Brazil’s population of 210 million. The unprotected CFPs were linked to people’s basic contact information, financial accounts, credit and debit history, voting history family relations and more, InfoArmor says. The company’s researchers say they encountered the openly accessible HTTP server in March 2018 while scanning the web for compromised machines. Within the database, the file “index.html” had been renamed to “index.html_bkp,” which the report says made it visible to the public. Anyone who knew what they were looking for could have found it, InfoArmor says. While the data wasn’t discovered as part of a breach, the researchers caution […]

The post Misconfigured server exposed half of Brazilian taxpayer ID numbers: report appeared first on CyberScoop.

Continue reading Misconfigured server exposed half of Brazilian taxpayer ID numbers: report

Imperva, Allstate, & Sonatype – Business Security Weekly #98

Imperva acquires app security firm Prevoty in $140 million deal, Allstate accelerates expansion into Identity Protection with acquisition of InfoArmor, Sonatype receives $80 million investment from TPG, Very Good Security makes data unhackable with $8…. Continue reading Imperva, Allstate, & Sonatype – Business Security Weekly #98

Leveraging social media in advanced threat intelligence

In this podcast recorded at Black Hat USA 2017, Christian Lees, CISO at InfoArmor, discusses how leveraging social media helps to understand the motives and threat landscape from threat actors. Here’s a transcript of the podcast for your convenience. My name is Christian Lees, I’m the CISO of InfoArmor, also in charge of data feeds. Recently we spent a lot of time working on our social media platform. We really like to use this kind … More Continue reading Leveraging social media in advanced threat intelligence

InfoArmor: Actionable intelligence, comprehensive protection

The complex and evolving landscape of cybercrime introduces your business to new threats on a daily basis. Protecting your corporate assets against cyber attacks requires a combination of sophisticated technology, accurate threat intelligence data and expert strategy. In this podcast recorded at Black Hat USA 2017, Mike Kirschner, Senior Vice President of Advanced Threat Intelligence at InfoArmor, talks about how they offer operatively-sourced threat intelligence, specialized cyber security services and real-time, client-specific alerts to protect … More Continue reading InfoArmor: Actionable intelligence, comprehensive protection

Who is the GovRAT Author and Mirai Botmaster ‘Bestbuy’?

In February 2017, authorities in the United Kingdom arrested a 29-year-old U.K. man on suspicion of knocking more than 900,000 Germans offline in an attack tied to Mirai, a malware strain that enslaves Internet of Things (IoT) devices like security cameras and Internet routers for use in large-scale cyberattacks. Investigators haven’t yet released the man’s name, but news reports suggest he may be better known by the hacker handle “Bestbuy.” This post will follow a trail of clues back to one likely real-life identity of Bestbuy. Continue reading Who is the GovRAT Author and Mirai Botmaster ‘Bestbuy’?

InfoArmor: Operatively-sourced threat intelligence

In this podcast, Mike Kirschner, Senior Vice President of Advanced Threat Intelligence at InfoArmor, talks about this dark web operatively sourced intelligence firm that is really focused on dark web surveillance and sourcing of compromise and breach data through operative engagement. Here’s a transcript of the podcast for your convenience. Hi, I’m Mike Kirschner, I’m the Senior Vice President of InfoArmor Advanced Threat Intelligence Division. We are a dark web operatively sourced intelligence firm that … More Continue reading InfoArmor: Operatively-sourced threat intelligence

InfoArmor VigilanteATI: Threat intelligence from the Dark Web

InfoArmor has expanded its global customer base in the enterprise and SME/SMB sector with its award-winning VigilanteATI Advanced Threat Intelligence Platform and Investigative Services. These organizations are using VigilanteATI and VigilanteATI Accomplice to gain high value threat intelligence throughout the threat lifecycle. From preemptive attacks to post-breach attribution, VigilanteATI helps enterprises and organizations enhance their security posture. For the SME/SMB, VigilanteATI Accomplice is an ideal solution to mitigate risk where resources and expertise in IT … More Continue reading InfoArmor VigilanteATI: Threat intelligence from the Dark Web