720-891-1663

Feds Fine Capital One for Shoddy Cloud Security

Dial back your wayback machine to September of last year. Capital One announced a hack of their Amazon environment by an ex-Amazon employee the previous July that was possible to due an incorrect configuration of their security settings. Fast forward to today and the feds announced an $80 million fine for bad cloud hygiene. The […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Here is a Match – Lawyers+Security Pros

There are an amazing number of misconfigured Amazon S3 buckets. I have no clue why. No company should be in this boat any more. Truffle Security said that a team of there security pros STUMBLED across about 4,000 of them. What was in them? Login credentials – not great. Security keys – even worse. API […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Source Code from Dozens of Companies Stolen

Companies like Microsoft, Lenovo, GE, Nintendo and many others have created publicly visible repositories on places like Github. Some of these buckets are empty and some may legitimately be intended to be public. But those that contain access credentials – userids, passwords and API keys – likely are NOT intended to be public. Some of […]

Continue reading → [DISPLAY_ACURAX_ICONS]