Уровень 0 · материалов: 4
В кластер включаются документы о конкретных случаях критических провалов в безопасности из-за небрежности компаний, и исключаются общие руководства по защите данных без привязки к инцидентам.
Общие признаки: грубая халатность в защите данных, эксплуатация базовых уязвимостей, компрометация критической инфраструктуры и систем, критика отсутствия аудита безопасности
Группа выше: Халатность и провалы в безопасности
Смысл: The main idea is to expose the gross negligence of Gulfstream Security Systems in implementing basic cybersecurity measures, demonstrating that their 'secure' systems are easily exploitable, potentially compromising thousands of high-profile and government sites.
Expocod exposes a critical vulnerability in Gulfstream Security Systems that allows remote access to user data, camera feeds, and alarm controls for over 70,000 clients due to a lack of encryption and predictable token generation.
Смысл: The main idea is to demonstrate how critical infrastructure, such as city barriers, can be completely compromised due to basic web vulnerabilities like ID enumeration and lack of access control, emphasizing the need for professional security audits in non-IT companies.
Security researchers exploited simple ID manipulation vulnerabilities in a barrier management system to gain full administrative control over thousands of Moscow barriers and resident data.
Смысл: The main idea is that Sony's repeated security breaches, specifically the LulzSec attack on Sony Pictures, were the result of gross negligence—using outdated software and plaintext passwords—leading to severe financial and reputational damage.
The hacking group LulzSec stole a million accounts from Sony Pictures using a simple SQL injection, highlighting Sony's systemic security negligence and causing a crash in their stock price.
Смысл: The main idea is that the rapid deployment of GPON networks by MGTS prioritized scale over security, leaving millions of users vulnerable to hacking due to predictable passwords and hardcoded hardware flaws.
MGTS GPON users are at high risk of network breaches due to predictable default passwords and a universal WPS vulnerability in ZTE routers.