Here are a handful of the most significant #AppSec news items from February 2019.
More raw material for Credential stuffing attacks are turning up
Some of the major hacks in the last few years that haven’t leaked out are now turning up for sale. An unidentified hacker has released at least 3 rounds of these credentials for sale, with the last round costing about $9350. They have claimed that the databases include credentials for Pizap, who’ve stated that they are not aware of a hack and will investigate immediately.
Credential stuffing is the automated injection of breached username/password pairs in order to fraudulently gain access to user accountsClick To Tweet
Meanwhile, IBM’s 2018 data breach study reveals that 74% of Data Breaches start with Privileged Credential Abuse.
Facebook CSRF protection bypass
CSRF, or Cross-Site Request Forgery, may no longer be part of the OWASP Top 10 list, but that does not mean that hackers are not looking to exploit these vulnerabilities. Samm0uda has posted a bug bounty writeup of their bypass of Facebook’s CSRF protection to perform an Account Takeover.
Public Facing APIs reveal a lot of information…including Identity numbers
JonLuca writes about their experiments with exploring the ways various companies perform A/B testing. There a lot of interesting information available, and this is an absolutely fascinating read.
A lot of people are exploring APIs to identify various things, and an ethical hacker discovered what could be a huge data breach of identity numbers from an Indian LPG company.
As we’ve noted earlier, API protection is absolutely a requirement today.APIs require significant security to ensure that they don’t become the all-new happy hunting ground for hackers. #DevSecOps #BarracudaBlogClick To Tweet
And another critical vulnerability in Drupal.
Magecart isn’t going away either, and it’s rapidly evolving. This time it’s the turn of Topps.com. Meanwhile, the group behind the malware is improving it, in a sign that it is extremely effective.
Get protection for websites and applications from cyber-threats with the Barracuda Web Application Firewall. Visit our corporate site here to learn more and get a free 30-day trial.
Tushar Richabadas est Senior Product Marketing Manager, Applications and Cloud Security chez Barracuda. Auparavant, il était responsable des produits Web Application Firewall et Load Balancer ADC de Barracuda, et son travail portait plus particulièrement sur le cloud et l'automatisation. Tushar possède une expérience très variée, allant de la gestion des équipes chargées de tester les produits de mise en réseau, à la gestion du marketing technique chez HCL-Cisco. Il suit de près l'évolution rapide de la sécurité numérique et a à cœur de simplifier les choses pour tous dans ce domaine.