Get a Pentest and security assessment of your IT network.

News

Exposed database allowed read/write access to Microsoft’s career portal

A jobs portal used by Microsoft applicants had a misconfigured MongoDB installation that exposed some information and enabled read/write access to the website. The database itself is maintained by Punchkick Interactive, a mobile development company contracted by Microsoft to run mcareersat.com. An attacker could have leveraged this exposure for a watering hole attack. The incident highlights the importance of monitoring and verification when it comes to outsourced development projects and third-party vendors. Microsoft responded swiftly and fixed the problem once alerted to the problem.”]

Source: https://www.csoonline.com/article/3033154/exposed-database-allowed-read-write-access-to-microsofts-career-portal.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2