Get a Pentest and security assessment of your IT network.

News

Imperva’s Breach Post-Mortem: API Key Left Exposed

Imperva CEO Chris Hylen offers a more detailed post-mortem on what went wrong. The company says it made a critical mistake leaving an internal compute instance containing the AWS API key accessible from the internet. The leaked data included email addresses, salted and hashed passwords, and for some customers, API and TLS keys. Imperva learned of the breach through a third party requesting a bug bounty Its unclear if the security company paid a bounty; Imperva is listed on bug bounty management company HackerOne’s directory.”]

Source: https://www.govinfosecurity.com/impervas-breach-post-mortem-api-key-left-exposed-a-13238

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2