article thumbnail

Thomson Reuters collected and leaked at least 3TB of sensitive data

Security Affairs

A thorough inspection of the SSL (secure sockets layer) certificate of the accessible web server, DNS (domain name system) data, and information on the ElasticSearch instance itself allowed the team to confirm that the open database belongs to the Thomson Reuters Corporation. “We Why did it happen? Exposed in the past?

IoT 127
article thumbnail

The Bug Report – November Edition

McAfee

CVE-2021-20322: Of all the words of mice and men, the saddest are, “it was DNS again.” Users of popular DNS service Quad9 have particular cause for concern, as the paper claims it falls under the vulnerable 13.85%. Your Cybersecurity Comic Relief . Why am I here? . Truly nefarious. . What can I do? .

DNS 90
article thumbnail

The Renaissance of NTLM Relay Attacks: Everything You Need to Know

Security Boulevard

This is the infamous ADCS ESC8 that Will Schroeder and Lee Chagolla-Christensen disclosed in their Certified Pre-Owned whitepaper. But how can we get DNS resolution for our attacker-controlled host? The ADCS Certificate Authority Web Enrollment endpoint and Certificate Enrollment Web Service run on IIS.