Pen-testing experts have made a worrisome discovery regarding the popular cloud storage service Box, specifically the Enterprise version used by some of the worlds biggest companies. They found that links to sensitive internal files can be determined by brute forcing them (i.e. guessing them) resulting in the exposure of terabytes of sensitive data. This is not a bug, the team notes, but rather a misuse of the shared folders functionality. The latter updated its shared links documentation to clarify what companies need to do to keep their Box shared files and folders secure.”]