• Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions
Flyy Tech
  • Home
  • Apple
  • Applications
    • Computers
    • Laptop
    • Microsoft
  • Security
  • Smartphone
  • Gaming
  • Entertainment
    • Literature
    • Cooking
    • Fitness
    • lifestyle
    • Music
    • Nature
    • Podcasts
    • Travel
    • Vlogs
  • Camera
  • Audio
No Result
View All Result
  • Home
  • Apple
  • Applications
    • Computers
    • Laptop
    • Microsoft
  • Security
  • Smartphone
  • Gaming
  • Entertainment
    • Literature
    • Cooking
    • Fitness
    • lifestyle
    • Music
    • Nature
    • Podcasts
    • Travel
    • Vlogs
  • Camera
  • Audio
No Result
View All Result
Flyy Tech
No Result
View All Result

Hundreds of Amazon RDS Snapshots Discovered Leaking Users’ Data

flyytech by flyytech
November 17, 2022
Home Security
Share on FacebookShare on Twitter


Hundreds of Amazon relational database service (RDS) instances have been found exposed monthly, with extensive leakage of personally identifiable information (PII).

The discovery has been made by security researchers at Mitiga, who published a post about the findings on Wednesday.

The Platform-as-a-Service (PaaS) tool, first released by Amazon in 2009, provides a database platform based on various optional engines (e.g., MySQL, PostgreSQL, etc.).

When using the RDS service in AWS, users can deploy RDS snapshots to back up the entire database (DB) instance instead of individual databases.

Snapshots can then be shared across different AWS accounts, both internal and external to an organization. Public RDS snapshots, in particular, allow users to share public data or a template database with an application.

“With that, one might unintentionally leak sensitive data to the world, even if you use highly secure network configuration,” Mitiga wrote in the advisory.

Case in point: the company found several snapshots that had been shared publicly for a few hours, days and even weeks, either intentionally or by mistake.

“It’s important to note that making a snapshot public, even for a very short amount of time, can have unwanted outcomes. Our research shows how a threat actor might take advantage of snapshots that are shared for even a short timeframe,” Mitiga wrote in its advisory.

According to Erich Kron, security awareness advocate at KnowBe4, while cloud storage is convenient, it can also be tricky to secure for people unfamiliar with it.

“The ability to do snapshots and share them, while very convenient, it’s something that can easily lead to issues that leave information exposed.”

The executive explained that while poorly configured permissions within an on-premise network are still a serious issue, the likelihood of a misconfiguration exposing information to millions of other people can be much lower.

“For organizations that store or process data within the cloud, processes should be in place to ensure that data remains protected even after making changes,” Kron told Infosecurity.

“The practice of having a second person confirm the permissions on data, while it can be inconvenient, can potentially save a lot of labor and the potential for fines, especially in heavily regulated industries.”

The Mitiga advisory comes two months after Snyk suggested 80% of organizations suffered a “severe” cloud security incident over the past year.



Source_link

flyytech

flyytech

Next Post
Scalpers Selling RTX 4080 For Over $1,600 Day After Launch

Scalpers Selling RTX 4080 For Over $1,600 Day After Launch

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended.

Download M2 MacBook Pro Schematic wallpapers

Download M2 MacBook Pro Schematic wallpapers

February 26, 2023
Qualcomm Unveils Snapdragon 8 Gen 2 Mobile Platform With Faster, More Intelligent Everything

Qualcomm Unveils Snapdragon 8 Gen 2 Mobile Platform With Faster, More Intelligent Everything

November 16, 2022

Trending.

Shop now. Pay later. on the App Store

Shop now. Pay later. on the App Store

February 25, 2023
Volla Phone 22 review

Volla Phone 22 review

March 26, 2023
USIU student team qualifies for Microsoft Imagine Cup World Championship

USIU student team qualifies for Microsoft Imagine Cup World Championship

April 5, 2023
Light Lens Lab 50mm f/2 Review: The Classic Speed Panchro II Reborn

Light Lens Lab 50mm f/2 Review: The Classic Speed Panchro II Reborn

March 22, 2023
Google 3D animals & AR objects: Full list & gallery

Google 3D animals & AR objects: Full list & gallery

December 27, 2022

Flyy Tech

Welcome to Flyy Tech The goal of Flyy Tech is to give you the absolute best news sources for any topic! Our topics are carefully curated and constantly updated as we know the web moves fast so we try to as well.

Follow Us

Categories

  • Apple
  • Applications
  • Audio
  • Camera
  • Computers
  • Cooking
  • Entertainment
  • Fitness
  • Gaming
  • Laptop
  • lifestyle
  • Literature
  • Microsoft
  • Music
  • Podcasts
  • Review
  • Security
  • Smartphone
  • Travel
  • Uncategorized
  • Vlogs

Site Links

  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions

Recent News

How to Unlock Any Phone Password without Losing Data [2023]

How to Unlock Any Phone Password without Losing Data [2023]

May 29, 2023
Nvidia Unveils DGX GH200 Supercomputer, Grace Hopper Superchips in Production

Nvidia Unveils DGX GH200 Supercomputer, Grace Hopper Superchips in Production

May 29, 2023

Copyright © 2022 Flyytech.com | All Rights Reserved.

No Result
View All Result
  • Home
  • Apple
  • Applications
    • Computers
    • Laptop
    • Microsoft
  • Security
  • Smartphone
  • Gaming
  • Entertainment
    • Literature
    • Cooking
    • Fitness
    • lifestyle
    • Music
    • Nature
    • Podcasts
    • Travel
    • Vlogs

Copyright © 2022 Flyytech.com | All Rights Reserved.

What Are Cookies
We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
Cookie SettingsAccept All
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT