Security giant Rubrik says hackers used Fortra zero-day to steal internal data

Silicon Valley-based data security company Rubrik has come forward as the latest victim of a zero-day vulnerability in Fortra GoAnywhere. The vulnerability is related to hacks targeting hospital chains and banks.

In a blog post published on Tuesday, Rubrik’s chief information security officer, Michael Mestrovich, said a flaw in Fortra’s GoAnywhere file transfer software, which Rubrik uses for internal sharing, allowed attackers to expose the company to injustice. You said you had access to a production IT test environment. data.

The vulnerability, tracked as CVE-2023-0669, was first disclosed on February 2, when security journalist Brian Krebs published details in a Fortra paywall security advisory. Fortra five days later he released a patch for the actively exploited flaw on February 7th.

According to Mestrovich, since learning of the vulnerability last month, Rubrik has conducted a “comprehensive review” of the affected data with an unnamed third-party company, and that the data accessed was primarily “a It consists of Rubrik’s internal sales information, including its partners.” Company name, business contact information, and a limited number of rubric purchase orders from his distributors. “

“Third-party companies also ensure that sensitive personal data such as social security numbers, financial account numbers, and payment card numbers are not exposed,” Mestrovich said.

Rubrik provides enterprise data management and backup services across on-premises, cloud, and hybrid networks.

In a statement, Rubrik spokesperson Najah Simmons told TechCrunch, “Unauthorized access does not include data that we protect on behalf of our customers through Rubrik products.” Simmons declined to answer additional questions, such as whether Rubrik received or was aware of the payment request.

Rubrik’s confirmation came just hours after the company’s name was listed on the Clop ransomware gang’s dark web leak site. The stolen data sample published by Clop and confirmed by TechCrunch is consistent with his Rubrik statement that it consists mostly of corporate information.

The Russia-linked Clop gang claims to have exploited zero-day vulnerabilities to steal data from over 130 organizations, including Hatch Bank and Community Health Systems. medical claims and insurance information, diagnostic and medication data, social security numbers;

Back in 2019, Rubrik suffered a security breach exposing its vast database of customer information. Dozens of gigabytes of data, including customer names, contact information, and casework for each corporate customer, on a public, password-protected server accessible to anyone who knows her IP address on the server. was left.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *