• Login
Fintedex — Business, Fincance & Investment News
  • Contact
  • Submit a News Releases
No Result
View All Result
  • Contact
  • Submit a News Releases
No Result
View All Result
Fintedex — Business, Fincance & Investment News
No Result
View All Result
Home Technology

Sega left a huge database of user information open to hackers

Timothy Wilson by Timothy Wilson
31.12.2021
in Technology
0
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Sega Europe could have easily fallen victim to a data breach as security researchers recently discovered that the company had left sensitive files stored insecurely on a publicly accessible database.

Researchers at the security firm VPN Overview found the files in question stored on a misconfigured Amazon Web Services (AWS) S3 bucket. They were also able to obtain multiple sets of AWS keys that gave them read and write access to Sega Europe’s cloud storage.

In addition to sensitive files, the misconfigured S3 bucket contained was also used to host websites for a number of popular Sega properties including Sonic the Hedgehog, Bayonetta, Football Manager and Total War as well as Sega’s official site. In total, 26 public-facing domains controlled by Sega Europe were affected.

VPN Overview’s researchers were able to upload files, execute scripts, alter existing web pages and modify the configuration of critically vulnerable Sega domains according to a new report.

Compromised email and cloud services

During its investigation, VPN Overview’s security team recovered an API to the email marketing software MailChimp that gave it the ability to send emails from the address [email protected]

The team then sent multiple messages to test its access and every email it sent appeared legitimate and also used TLS encryption. From here, the researchers were able to alter existing MailChimp templates and even create their own. As all of the emails sent out to Football Manager users appeared legitimate and would be able to bypass email security checks, a malicious attacker could have used this access to launch phishing campaigns.

VPN Overview was also able to upload and replace files on three of Sega’s content delivery networks (CDNs). As third-party websites often link to a company’s CDN for an official version of an image or file, 531 additional domains were linked to Sega Europe’s affected CDNs. As a result, an attacker could have abused the company’s CDNs to distribute malware and ransomware to unsuspecting users.

After discovering Sega Europe’s misconfigured S3 bucket, VPN Overview responsibly disclosed its findings to the company which then secured the database and all of its  affected cloud services and software.

We’ve also featured the best antivirus and best password manager


Previous Post

Dow Jones Newswires: China steps in to help another property developer in distress

Next Post

The New York Post: Chicago teacher learns she’s COVID-positive while en route to Iceland — and self-quarantines in airplane toilet for four hours

Related Posts

Some Windows updates might actually hurt your security
Technology

Some Windows updates might actually hurt your security

by Timothy Wilson
16.05.2022
Tech Moves: Longtime Microsoft leader James Phillips leaves Stripe; and more
Technology

Tech Moves: Longtime Microsoft leader James Phillips leaves Stripe; and more

by Timothy Wilson
16.05.2022
It looks like Apple WWDC 2022 will be in-person after all – for some
Technology

It looks like Apple WWDC 2022 will be in-person after all – for some

by Timothy Wilson
16.05.2022
Save up to $700 during Nolah Mattress’ Memorial Day Sale
Technology

Save up to $700 during Nolah Mattress’ Memorial Day Sale

by Timothy Wilson
16.05.2022
Report: Apple bringing USB-C to the iPhone but not the iPhone 14
Technology

Report: Apple bringing USB-C to the iPhone but not the iPhone 14

by Timothy Wilson
16.05.2022
Next Post

The New York Post: Chicago teacher learns she’s COVID-positive while en route to Iceland — and self-quarantines in airplane toilet for four hours

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Premium Content

Studying how the first era of globalisation ended could help preserve the second

24.02.2022

OnePlus 10 Pro vs Google Pixel 6 Pro: Android Pro face-off

07.03.2022

Kelley Blue Book: The 2022 Toyota Corolla vs. the Nissan Sentra—which is better?

30.12.2021

Browse by Category

  • Business
  • Finance
  • Stock Market
  • Technology
  • Без рубрики

Browse by Tags

Europe Oleg Volin Russia Ukraine

Fintedex delivers real-time news about the financial industry: feature stories, industry developments, opinions plus the latest on people and trends.

Categories

  • Business
  • Finance
  • Stock Market
  • Technology
  • Без рубрики

Browse by Tag

Europe Oleg Volin Russia Ukraine

Recent Posts

  • The Location Guide, Filmmakers for Ukraine and EUFCN join forces for fundraiser at Cannes 2022
  • Free exchange: The world needs a new economic motor. Could India fit the bill?
  • Buttonwood: Why Italy’s borrowing costs are surging once again

© 2021 Fintedex.

No Result
View All Result
  • Contact
  • Submit a News Releases

© 2021 Fintedex.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?