Breaking News

PlayStation Plus Game Catalog for August 2025 Arctic announces Xtender PC case Samsung Launches World’s First 500Hz OLED Gaming Monitor and New Odyssey G7 Lineup Razer Unveils Wolverine V3 Pro 8K PC controller XPG Launches the Industry-leading RGB Gen4 SSD – SPECTRIX S65G

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Unpatched Software Led to Massive Equifax Breach

Unpatched Software Led to Massive Equifax Breach

Enterprise & IT Sep 14,2017 0

The Equifax breach that exposed sensitive data for as many as 143 million US consumers was accomplished by exploiting a Web application vulnerability, company officials said Thursday.

"Equifax has been intensely investigating the scope of the intrusion with the assistance of a leading, independent cybersecurity firm to determine what information was accessed and who has been impacted," company officials wrote in an update posted online. "We know that criminals exploited a US website application vulnerability. The vulnerability was Apache Struts CVE-2017-5638. We continue to work with law enforcement as part of our criminal investigation, and have shared indicators of compromise with law enforcement."

The flaw in the Apache Struts framework was fixed on March 6. Three days later, the bug was already under mass attack by hackers who were exploiting the flaw to install rogue applications on web servers.

The disclosure suggests that Equifax failed to update its Web applications, despite demonstrable proof the bug gave real-world attackers an easy way to take control of sensitive sites.

Equifax Chief Executive Richard Smith is expected to testify before a U.S. House of Representatives panel on Oct. 3 after nearly 40 states joined a probe of the company's handling of the breach.

The Federal Trade Commission on Thursday said it has opened an investigation into the data breach at Equifax.

Apache Struts is a framework for developing Java-based apps that run both front-end and back-end Web servers. It's relied on heavily by banks, government agencies, large Internet companies, and Fortune 500 companies.

Tags: EquifaxHacking
Previous Post
Apple Explains the 'Failed' Face ID Demo on iPhone X event
Next Post
Samsung to Create US$300 Million Fund for Auto-related Technologies

Related Posts

  • MSI has been hacked, be warned about where you download files

  • Hackers gain access to PS5 Debug Menu and show decrypted PS5 firmware files

  • HP Threat Research Shows Attackers Exploiting Zero‐Day Vulnerability Before Enterprises Can Patch

  • EA Gets hacked - 780GB of data and sourcecode stolen

  • European Supercomputers Researching Covid-19 Report Hacking Attacks

  • Microsoft Offers You $100,000 If You Can Hack the Linux-based Azure Sphere

  • Zoom Users' Data have Been on Sale on Dark Web: report

  • Indonesia's Tokopedia Inverstigates Alleged Data Leak of 91 Million Users

Latest News

PlayStation Plus Game Catalog for August 2025
Gaming

PlayStation Plus Game Catalog for August 2025

Arctic announces Xtender PC case
Cooling Systems

Arctic announces Xtender PC case

Samsung Launches World’s First 500Hz OLED Gaming Monitor and New Odyssey G7 Lineup
Gaming

Samsung Launches World’s First 500Hz OLED Gaming Monitor and New Odyssey G7 Lineup

Razer Unveils Wolverine V3 Pro 8K PC controller
Gaming

Razer Unveils Wolverine V3 Pro 8K PC controller

XPG Launches the Industry-leading RGB Gen4 SSD – SPECTRIX S65G
PC components

XPG Launches the Industry-leading RGB Gen4 SSD – SPECTRIX S65G

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Noctua NH-D15 G2

Noctua NH-D15 G2

Soundpeats Pop Clip

Soundpeats Pop Clip

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

be quiet! Pure Base 501

be quiet! Pure Base 501

Terramaster F8-SSD

Terramaster F8-SSD

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed