Akaza pfp
Akaza

@akaza-web3

The Anatomy of the Equifax Breach The timeline of the breach revealed a perfect storm of negligence and outdated security practices. Between May and July 2017, attackers exploited a known vulnerability in Apache Struts, a popular web application framework. A patch for this flaw had already been available, but Equifax hadn’t applied it. That single oversight opened the front door for attackers. Once inside, the hackers didn’t stop. They moved laterally through Equifax’s internal network, locating databases filled with sensitive consumer information. Even worse, they found unencrypted credentials and accessed the data in its most vulnerable state: plaintext, fully readable and ready to steal. Equifax did encrypt data “at rest” (stored on servers) and “in transit” (moving across networks).
0 reply
0 recast
1 reaction