, , , , ,

Security giant Rubrik says hackers used Fortra zero-day to steal internal data

Silicon Valley-based data security company Rubrik has come forward as the latest victim of the Fortra GoAnywhere zero-day vulnerability, which has been linked to hacks targeting a hospital chain and a bank.

In a blog post published on Tuesday, Rubrik’s chief information security officer Michael Mestrovich said that attackers had gained access to the company’s non-production IT testing environments as a result of the flaw in Fortra’s GoAnywhere file-transfer software, which Rubrik uses for sharing internal data.

This vulnerability, tracked as CVE-2023-0669, first came to light on February 2 after security journalist Brian Krebs publicly shared details of Fortra’s paywalled security advisory. Fortra released a patch for the actively-exploited flaw five days later on February 7.

Mestrovich said that since learning of the flaw last month, Rubrik conducted a “comprehensive review” of the affected data with an unnamed third-party firm, which found that the data accessed mainly consists of Rubrik internal sales information, including “certain customer and partner company names, business contact information, and a limited number of purchase orders from Rubrik distributors.”

“The third-party firm has also confirmed that no sensitive personal data such as Social Security numbers, financial account numbers, or payment card numbers were exposed,” Mestrovich said.

Rubrik provides enterprise data management and backup services across on-premise, cloud and hybrid networks.

In a statement, Rubrik spokesperson Najah Simmons told TechCrunch that the “unauthorized access did not include any data we secure on behalf of our customers via any Rubrik products.” Simmons declined to answer any additional questions, such as whether Rubrik has received or been made aware of a demand for payment.

Rubrik’s confirmation comes just hours after a listing naming the company appeared on the dark web leak site of the Clop ransomware gang. Samples of stolen data published by Clop, and seen by TechCrunch, align with Rubrik’s statement that it comprised of mostly corporate information.

The Russia-linked Clop gang claims to have exploited the zero-day flaw to steal data from more than 130 organizations — including Hatch Bank, and Community Health Systems, which last week confirmed in a filing with the Maine attorney general’s office that the hackers accessed medical billing and insurance information, diagnostic and medications data, and Social Security numbers.

Back in 2019, Rubrik suffered a security lapse that exposed a massive database of customer information. An exposed server that wasn’t protected with a password left tens of gigabytes of data, including customer names, contact information and casework for each corporate customer, accessible to anyone who knew the IP address of the server.

Security giant Rubrik says hackers used Fortra zero-day to steal internal data by Carly Page originally published on TechCrunch

https://techcrunch.com/2023/03/14/security-giant-rubrik-says-hackers-used-fortra-zero-day-to-steal-internal-data/


July 2024
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  

About Us

Welcome to encircle News! We are a cutting-edge technology news company that is dedicated to bringing you the latest and greatest in everything tech. From automobiles to drones, software to hardware, we’ve got you covered.

At encircle News, we believe that technology is more than just a tool, it’s a way of life. And we’re here to help you stay on top of all the latest trends and developments in this ever-evolving field. We know that technology is constantly changing, and that can be overwhelming, but we’re here to make it easy for you to keep up.

We’re a team of tech enthusiasts who are passionate about everything tech and love to share our knowledge with others. We believe that technology should be accessible to everyone, and we’re here to make sure it is. Our mission is to provide you with fun, engaging, and informative content that helps you to understand and embrace the latest technologies.

From the newest cars on the road to the latest drones taking to the skies, we’ve got you covered. We also dive deep into the world of software and hardware, bringing you the latest updates on everything from operating systems to processors.

So whether you’re a tech enthusiast, a business professional, or just someone who wants to stay up-to-date on the latest advancements in technology, encircle News is the place for you. Join us on this exciting journey and be a part of shaping the future.

Podcasts

TWiT 986: Our Dope GPS! – Supreme Court Decisions, Snapdragon X Elite Tests This Week in Tech (Audio)

Supreme Court Decisions, Snapdragon X Elite Tests Murthy Decision Should Not Foreclose Cases Against Actual First Amendment Violations What SCOTUS just did to broadband, the right to repair, the environment, and more Nearly 4,000 arrested in global police crackdown on online scam networks Mark Cuban's public email was hacked after receiving call from a fake Google rep The Julian Assange Saga Is Finally Over Microsoft's bundling of Office and Teams breaks antitrust law, EU says EU Competition Commissioner says Apple's decision to pull AI from EU shows anticompetitive behavior Microsoft says it's okay to steal content published on the web Microsoft's Surface Laptop 7 Copilot+ PC is finally the best clamshell laptop on the market after 8 years of iterations Tested: Don't buy a Snapdragon X Elite laptop for PC gaming Signal 65 Snapdragon battery testing The RIAA's lawsuit against generative music startups will be the bloodbath AI needs Wherein The Copia Institute Asks The Second Circuit To Stand Up For Fair Use, The Internet Archive, And Why We Bother To Have Copyright Law At All Redbox's owner files for bankruptcy after repeatedly missing payments and payroll Host: Leo Laporte Guests: Cathy Gellis, Ryan Shrout, and Doc Rock Download or subscribe to this show at https://twit.tv/shows/this-week-in-tech Get episodes ad-free with Club TWiT at https://twit.tv/clubtwit Sponsors: lookout.com 1password.com/twit
  1. TWiT 986: Our Dope GPS! – Supreme Court Decisions, Snapdragon X Elite Tests
  2. TWiT 985: TikTok With Wings – AT&T Landlines, US Bans Kaspersky and DJI
  3. TWiT 984: Fifty-three Clicks – Bot Farms in Ukraine, LA Public Health Dept. Phished
  4. TWiT 983: Digital Snackwells – NVIDIA's Thor, Adobe's TOS, Insta's Unskippable Ads
  5. TWiT 982: International Trash – Startup Chaos, Breaking Ticketmaster, Ultrasonic Coffee