Equifax has disclosed further details of data that was breached in its cybersecurity incident in September. IT security experts commented below.
Gavin Millard, Technical Director at Tenable:
“The data exposed in the Equifax breach could easily be leveraged for targeted fraud against those 146 million who were caught up in it. Social security numbers, dates of birth and other personal information could be used by criminals to setup loans, credit cards and other methods of monetising the data lost.
“When a single vulnerability affecting a web application can be leveraged to swipe so much data, it’s time to take foundational security seriously.”
Mounir Hahad, Head of Juniper Threat Labs at Juniper Networks:
“Eight days into May 2018 and there are already 156 vulnerabilities reported. Most of them will have patches available, but the vast majority of vulnerable systems will remain unpatched long enough for a cyber attacker to take advantage of the window of opportunity. Cyber threat actors understand this behavior and have developed processes for integrating exploit code as quickly as proofs of concepts are posted on Pastebin.com. Sometimes they don’t wait for a PoC and develop their own working attack within hours or days of a vulnerability being disclosed.
“It is criminal in my opinion to knowingly postpone a security update beyond a reasonable amount of time and suffer a breach as a consequence. EternalBlue does not have to be eternal, we have the power to turn it into LegacyBlue by patching our systems.”
Nick Bilogorskiy, Cybersecurity Strategist at Juniper Networks:
“Equifax vulnerability CVE-2017-5638 allowed unauthenticated remote code execution on Java web applications via the REST plugin with XStream handler to handle XML payloads.This vulnerability was fixed in the Apache Struts version 2.5.13 in September 2017.
“In 2016, known vulnerabilities were the leading cause of data breaches, accounting for 44 percent of all such incidents. I highly recommend that organizations apply critical security patches within one week of their release in order to reduce the known threat attack surface. Otherwise, it’s the same as buying expensive locks for the doors to your home but keeping the windows wide open.”
The opinions expressed in this post belongs to the individual contributors and do not necessarily reflect the views of Information Security Buzz.