Get a Pentest and security assessment of your IT network.

News

Hilton Honors accounts exposed due to a CRFS flaw

Security experts discovered a CSRF vulnerability in the Hilton website that could be exploited by attackers to take over every Hilton Honors account. Experts discovered that any authenticated users could impersonate any another account by knowing its account number. The vulnerability was uncovered by Brandon Potter and JB Snyder, technical security consultant and founder at security firm Bancsec. The flaw was fixed and there is no more news about it, but Krebs verified it with the support of the researchers using his personal account. Hilton issued an official statement confirming the presence of the vulnerability: We are committed to safeguarding our guests personal information”]

Source: https://securityaffairs.co/wordpress/35261/hacking/hilton-honors-accounts-exposed-due-to-a-crfs-flaw.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Russian cybercriminal Roman Seleznev gets another prison sentence