Nextgov Staff | Nextgov | March 6, 2017 | 0 Comments

Slack and Teddy Bears Leak Your Secrets; Boeing Employee Sends Personnel Data to His Wife

Kidsada Manchinda/Shutterstock.com

In case you missed our coverage this week in ThreatWatchNextgov’s regularly updated index of cyber breaches:

Slack Quickly Patches Bug That Allowed Access to Chats

Slack, a team messaging app, in five hours patched a bug that allowed a hacker access to a user’s communications.

That includes all the private messages where users may be less likely to talk strictly work.

Detectify Labs security researcher Frans Rosén determined he could steal users' private tokens—which allow access to the user’s communications—by tricking them with a malicious web page.

According to Rosén, Slack responded to his first notification 33 minutes after he sent it and resolved the issue within five hours. The company also paid him $3,000 for reporting the bug.

Internet-Connected Teddy Bear Don't Keep Secrets

A high-tech toy teddy bear exposed more than 2 million voice messages from children and parents by using poor security practices, according to a security researcher.

Spiral Toys’ CloudPets brand of internet toys reads like a list of security don’ts. The company stored customer credentials in a publicly available online database that didn’t require a password and wasn’t behind a firewall while it put audio messages in an Amazon-hosted service that didn’t require authorization, according to a Feb. 27 blog by Troy Hunt, who maintains Have I Been Pwned? breach notification service.

The company hashed customers’ credentials, but it didn’t establish any password strength requirements so capable hackers would be able to crack large chunks of the more than 800,000 credentials, Hunt wrote. Some passwords, for example, were a single letter or commonly used passwords like “password,” “123456” and “cloudpets.”

The data was exposed from Christmas to sometime in January, and Motherboard reports it was also accessed and held for ransom multiple times in a wave of attacks on MongoDB databases.

Hunt says the company was alerted several times about the breach, but never responded. Mark Myers, Spiral Toys CEO, told Network World no voice recordings were stolen.

“Circling back to the parents' position for a moment, you must assume data like this will end up in other peoples' [sic] hands,” Hunt wrote. “Whether it's the Cayla doll, the Barbie, the VTech tablets or the CloudPets, assume breach. It only takes one little mistake on behalf of the data custodian—such as misconfiguring the database security—and every single piece of data they hold on you and your family can be in the public domain in mere minutes.”

Boeing Employee Emails 36,000 Coworkers' Personal Info to Spouse

Boeing has started notifying the 36,000 employees whose personal information was mistakenly leaked via email, according to Threatpost.

A Boeing employee had a problem formatting a spreadsheet and emailed it to his spouse for help, wrote Boeing Deputy Chief Privacy Officer Marie Olson in a letter to the Washington State attorney general notifying the state of the data breach.

The spreadsheet contained names, birthdates, Social Security numbers, and other accounting code and employee identification information—but tucked away in “hidden” columns. The employee sent the email Nov. 21, though it wasn’t discovered until January.

Boeing is offering employees two years of identity protection services.

Comments
JOIN THE DISCUSSION

Thank you for subscribing to newsletters from Nextgov.com.
We think these reports might interest you:

  • Modernizing IT for Mission Success

    Surveying Federal and Defense Leaders on Priorities and Challenges at the Tactical Edge

    Download
  • Communicating Innovation in Federal Government

    Federal Government spending on ‘obsolete technology’ continues to increase. Supporting the twin pillars of improved digital service delivery for citizens on the one hand, and the increasingly optimized and flexible working practices for federal employees on the other, are neither easy nor inexpensive tasks. This whitepaper explores how federal agencies can leverage the value of existing agency technology assets while offering IT leaders the ability to implement the kind of employee productivity, citizen service improvements and security demanded by federal oversight.

    Download
  • Effective Ransomware Response

    This whitepaper provides an overview and understanding of ransomware and how to successfully combat it.

    Download
  • Forecasting Cloud's Future

    Conversations with Federal, State, and Local Technology Leaders on Cloud-Driven Digital Transformation

    Download
  • IT Transformation Trends: Flash Storage as a Strategic IT Asset

    MIT Technology Review: Flash Storage As a Strategic IT Asset For the first time in decades, IT leaders now consider all-flash storage as a strategic IT asset. IT has become a new operating model that enables self-service with high performance, density and resiliency. It also offers the self-service agility of the public cloud combined with the security, performance, and cost-effectiveness of a private cloud. Download this MIT Technology Review paper to learn more about how all-flash storage is transforming the data center.

    Download

When you download a report, your information may be shared with the underwriters of that document.