Many Public Salesforce Sites are Leaking Private Data

A shocking number of organizations — including banks and healthcare providers — are leaking private and sensitive information from their public Salesforce Community websites, KrebsOnSecurity has learned. The data exposures all stem from a misconfiguration in Salesforce Community that allows an unauthenticated user to access records that should only be available after logging in. Continue reading Many Public Salesforce Sites are Leaking Private Data

Vermont Taxpayers Warned of Data Leak Over the Past Three Years

A vulnerability in the state’s system may have exposed personal data that can be used for credential theft for those who filed Property Transfer Tax returns online. Continue reading Vermont Taxpayers Warned of Data Leak Over the Past Three Years

Software Vulnerabilities Used by 200 VT Towns Left Employees’ SSNs Exposed

Vulnerabilities in software used by 200 Vermont municipalities left town employees’ Social Security Numbers and other information exposed. Brett Johnson, owner of IT company simpleroute, discovered the flaws after two Vermont towns hired him to d… Continue reading Software Vulnerabilities Used by 200 VT Towns Left Employees’ SSNs Exposed