{"id":182,"date":"2020-08-09T00:09:15","date_gmt":"2020-08-08T21:09:15","guid":{"rendered":"https:\/\/fierceonlinevideo.com\/?p=182"},"modified":"2020-10-27T03:23:59","modified_gmt":"2020-10-27T01:23:59","slug":"cyber-%e2%80%8b%e2%80%8bsecurity-company-information-revealed-among-other-things","status":"publish","type":"post","link":"https:\/\/fierceonlinevideo.com\/security\/cyber-%e2%80%8b%e2%80%8bsecurity-company-information-revealed-among-other-things\/","title":{"rendered":"Cyber \u200b\u200bsecurity company information revealed among other things"},"content":{"rendered":"
VpnMentor’s cybersecurity research team led by Noam Rotem and Ran Locar has revealed unprotected AWS S3 container with over 5.5 million files and over 343GB in size <\/strong>it is not required.<\/p>\n Sometimes the extent of data breaches and the owner of the data are obvious, and the problem was resolved quickly. But these times are rare. Most of the time, we need days of investigation before we understand what is at stake or who is disclosing the information.<\/strong><\/p>\n Understanding the violation and its potential impact takes careful attention and time. We work hard to publish accurate and reliable reports, making sure everyone who reads them understands their seriousness.<\/p>\n Some parties dispute the facts, ignore our research, or diminish its impact.<\/strong> So we need to be thorough and make sure everything we find is right and true.<\/p>\n In this case, after a few days of research, we recognized the possibility that the information belongs to InMotionNow and contacted the company later with our discovery<\/strong>. Although the unprotected S3 bucket is now closed, none of the company ever responded to attempts to gain access, so we cannot confirm ownership.<\/p>\n In this particular case, our research team was unable to verify without a shadow of a doubt who exactly owns the disclosed information. For this reason, we have decided that it is very important to let the general public know whose information and which information is vulnerable to the lack of standard cybersecurity procedures. <\/strong><\/p>\n Our research led us to it InMotionNow owns the data. We addressed them, and no one answered<\/strong>, and the bare bucket had no clear indication that it was theirs. With that in mind, we are including all companies whose information was found in the bucket<\/strong>. If it actually belongs to InMotionNow, they know who is disclosing the information, and if not, companies can investigate for themselves. Our team has also reached these companies on March 16, 2020.<\/strong><\/p>\n Founded in 1999, InMotionNow is a project management software company headquartered near Raleigh, North Carolina. They have FDA-compliant safety standards aimed at the verticals of their target customers.<\/p>\n Here is a non-exhaustive list of companies whose marketing material was found in an unprotected S3 bucket:<\/p>\n Cyber \u200b\u200bsecurity company ISC2.org<\/strong> several pieces of information were also included in this violation.<\/p>\n Brotherhood Mutual Insurance Company,<\/strong> which primarily serves religious institutions throughout the United States.<\/p>\n Universities such as the state of Kent in Ohio and Purdue in Indiana<\/strong>, The S3 group also contained numerous files and data.<\/p>\n Potawatomi Hotel & Casino<\/strong> in Milwaukee, Wisconsin.<\/p>\n Consumer Electronics Company, Zagg (ZAGG),<\/strong> which designs and produces mobile accessories.<\/p>\n A non-profit organization, the Freedom Forum Institute,<\/strong> which supports the United States \u2019First Amendment freedoms for all.<\/p>\n Organizations were found to be affected by different health care regulations. They include, but are not limited to:<\/p>\n Myriad genetics (MYGN)<\/strong> – Genetic and disease testing company.<\/p>\n Performance health<\/strong> – Provider of physiotherapy equipment and supplies.<\/p>\n Here is a list of information that our research team found and was able to identify:<\/p>\n Lists of university donors, including:<\/p>\n<\/span>Discovery timeline and owner reaction<\/h2>\n
\n
<\/span>Company profiles<\/h2>\n
<\/span>Examples of records<\/h2>\n
The data is affected<\/h3>\n
\n
\n
\n
\n