Newsletter
REAL HACKER NEWS
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
  • CAMERA
  • COMPUTERS
    • LAPTOP
  • APPLICATIONS
  • AUDIO
No Result
View All Result
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
  • CAMERA
  • COMPUTERS
    • LAPTOP
  • APPLICATIONS
  • AUDIO
No Result
View All Result
REAL HACKER NEWS
No Result
View All Result
Home APPLICATIONS

Researchers Discover Hundreds of Amazon RDS Instances Leaking Users’ Personal Data

Real Hacker Staff by Real Hacker Staff
November 16, 2022
in APPLICATIONS
0
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Related articles

Apple Music Classical Now Available to Download

March 28, 2023

Microsoft Introduces GPT-4 AI-Powered Security Copilot Tool to Empower Defenders

March 28, 2023


A whole lot of databases on Amazon Relational Database Service (Amazon RDS) are exposing private identifiable info (PII), new findings from Mitiga, a cloud incident response firm, present.

“Leaking PII on this method offers a possible treasure trove for menace actors – both through the reconnaissance section of the cyber kill chain or extortionware/ransomware campaigns,” researchers Ariel Szarf, Doron Karmi, and Lionel Saposnik stated in a report shared with The Hacker Information.

This contains names, e mail addresses, cellphone numbers, dates of start, marital standing, automobile rental info, and even firm logins.

Amazon RDS is an online service that makes it attainable to arrange relational databases within the Amazon Internet Providers (AWS) cloud. It affords help for various database engines corresponding to MariaDB, MySQL, Oracle, PostgreSQL, and SQL Server.

The basis explanation for the leaks stems from a characteristic known as public RDS snapshots, which permits for making a backup of the whole database setting operating within the cloud and might be accessed by all AWS accounts.

Amazon RDS Snapshots

“Be certain when sharing a snapshot as public that none of your non-public info is included within the public snapshot,” Amazon cautions in its documentation. “When a snapshot is shared publicly, it provides all AWS accounts permission each to repeat the snapshot and to create DB situations from it.”

The Israeli firm, which carried out the analysis from September 21, 2022, to October 20, 2022, stated it discovered 810 snapshots that have been publicly shared for various period, ranging from a couple of hours to weeks, making them ripe for abuse by malicious actors.

CyberSecurity

Of the 810 snapshots, over 250 of the backups have been uncovered for 30 days, suggesting that they have been doubtless forgotten.

Based mostly on the character of the data uncovered, adversaries may both steal the info for monetary acquire or leverage it to get a greater grasp of an organization’s IT setting, which may then act as a stepping stone for covert intelligence gathering efforts.

It is extremely really helpful that RDS snapshots will not be publicly accessible to be able to stop potential leak or misuse of delicate information or every other sort of safety menace. It is also suggested to encrypt snapshots the place relevant.






Source link

Tags: AmazonDataDiscoverHundredsInstancesLeakingPersonalRDSresearchersUsers
Share76Tweet47

Related Posts

Apple Music Classical Now Available to Download

by Real Hacker Staff
March 28, 2023
0

The app is all about showcasing the more than 5 million classical music tracks available on Apple Music. “We love...

Microsoft Introduces GPT-4 AI-Powered Security Copilot Tool to Empower Defenders

by Real Hacker Staff
March 28, 2023
0

î ‚Mar 28, 2023î „Ravie LakshmananArtificial Intelligence / Cyber Threat Microsoft on Tuesday unveiled Security Copilot in preview, marking its continued push...

Here’s what’s new in iPadOS 16.4, watchOS 9.4, macOS Ventura 13.3, and tvOS 16.4

by Real Hacker Staff
March 28, 2023
0

After weeks of betas, Apple has now made its iPadOS 16.4, watchOS 9.4, macOS Ventura 13.3, and tvOS 16.4 updates...

Apple Pay Later is here, but whether you can use or not it is completely random…

Apple Pay Later is here, but whether you can use or not it is completely random…

by Real Hacker Staff
March 28, 2023
0

Apple has today announced that it will start rolling out Apple Pay Later randomly to users in the U.S. starting...

How to enable cellular Voice Isolation on iPhone with iOS 16.4

by Real Hacker Staff
March 28, 2023
0

With the release of iOS 16.4, Apple has brought the fantastic Voice Isolation feature from FaceTime to cellular calls on...

Load More
  • Trending
  • Comments
  • Latest

eSIMs Will Transform the Way You Think About Mobile Data and Security

March 7, 2023

XMOS Launches XVF3800 High-Performance Voice Processor for Enterprise and Consumer Voice Conferencing Platforms

March 7, 2023

Chinese Hackers Using Russo-Ukrainian War Decoys to Target APAC and European Entities

December 7, 2022

Sennheiser Starts Shipping EW-DX Digital Wireless Microphone Series

November 22, 2022

Hello world!

0
US Commodities Regulator Beefs Up Bitcoin Futures Review

US Commodities Regulator Beefs Up Bitcoin Futures Review

0
Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

Bitcoin Hits 2018 Low as Concerns Mount on Regulation, Viability

0
India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

India: Bitcoin Prices Drop As Media Misinterprets Gov’s Regulation Speech

0
Part 1’s PC Port Isn’t In Great Shape Right Now

Part 1’s PC Port Isn’t In Great Shape Right Now

March 28, 2023
US bid to ban TikTok raises hypocrisy charge amid global spying | Social Media

US bid to ban TikTok raises hypocrisy charge amid global spying | Social Media

March 28, 2023
Apple Pay Later turns Apple into a full-on money lender

Apple Pay Later turns Apple into a full-on money lender

March 28, 2023
Covariant’s CEO on building AI that helps robots learn

Covariant’s CEO on building AI that helps robots learn

March 28, 2023

Recent News

Part 1’s PC Port Isn’t In Great Shape Right Now

Part 1’s PC Port Isn’t In Great Shape Right Now

March 28, 2023
US bid to ban TikTok raises hypocrisy charge amid global spying | Social Media

US bid to ban TikTok raises hypocrisy charge amid global spying | Social Media

March 28, 2023

Categories

  • APPLICATIONS
  • AUDIO
  • CAMERA
  • COMPUTERS
  • GAMING
  • LAPTOP
  • REVIEWS
  • SECURITY
  • SMARTPHONES
  • Uncategorized
REAL HACKER NEWS

We bring you the best news on Internet new gadgets hacking and technology from around the world

  • Contact
  • Cookie Privacy Policy
  • Terms and Conditions
  • Privacy Policy
  • Disclaimer
  • DMCA

© 2003 Real Hacker News

No Result
View All Result
  • Home
  • REVIEWS
  • SECURITY
  • GAMING
  • SMARTPHONES
  • CAMERA
  • COMPUTERS
    • LAPTOP
  • APPLICATIONS
  • AUDIO

© 2003 Real Hacker News

Go to mobile version