Trending

ee-track">
HomeBlog
Start Locking Down Your Elasticsearch Servers!!
Start Locking Down Your Elasticsearch Servers!!

Start Locking Down Your Elasticsearch Servers!!

As per David Baldacci “small mistakes tend to large ones. Ours is a lifetime appointment, and all you have is your reputation. Once it’s gone, it doesn’t come back”. In more precise and straightforward words, it means that a small mistake made by a company can ultimately lead to a substantial loss to them, which could be in the form of both monetary and non-monetary terms. For instance, recently, Cyble identified a data breach of the website “schoolcentre.com.au” due to an open ELK server which led to the exposure of over 2.16 million records of Australians.

1* u dH2dt MsSqNuYgAzRzg

Personal User Records of School Centre exposed via open ELK Server

Along with it, recently Blisk a well-known browser vendor also left its Elasticsearch server exposed online without a password which ultimately led to the exposure of around 2.9 million personal user records amounting for 3.4 GB of data. Talking about security breaches, till now, Cyble has uncovered more than 30.000 unreported data breaches which have affected more than 500 million accounts. Just recently, as per Blisk, its browser is used by more than 40000 companies which include some of the big companies such as NASA, HP, Deloitte, HP, and Xerox. So, in a way we can see that just because of a small mistake made by the Blisk company, it ultimately affected the personal records of such big companies.

1*5IPkBjaGLeavigyNgrCMUQ

Exposed Personal Details which includes email addresses and user-agent strings

In a recent report shared with ZDNet, the vpnMentor researchers Noam Rotem and Ran Locar stated that thousands of web developers all over the world were made vulnerable to online attacks and frauds due to the leakage of their details on Internet just because Blisk left an Elasticsearch server exposed online without the need of password to authenticate it. As per the online reports it is being discovered that overall the entire exposed or leaked data online could be used to target developers working for big private companies and develop malware based on the company’s user-agent strings which is a big concern for those companies at this point of time.

Not only that, but this leakage of sensitive information has affected Blisk users all across the globe. These types of information leakage not only affect the companies in monetary terms but also in non-monetary terms such as harming the company’s goodwill, affecting their customers and many more. Taking these points into consideration all the companies irrespective of their size should be focused on making themselves secure from such attacks or incidents.

report-ad-banner

About Cyble:

Cyble Inc.’s mission is to provide organizations with a real-time view of their supply chain cyber threats and risks. Their SaaS-based solution powered by machine learning and human analysis provides organizations’ insights to cyber threats introduced by suppliers and enables them to respond to them faster and more efficiently.

Cyble strives to be a reliable partner/facilitator to its clients allowing them with unprecedented security scoring of suppliers through cyber intelligence sourced from open and closed channels such as OSINT, the dark web and deep web monitoring and passive scanning of internet presence. Furthermore, the intelligence clubbed with machine learning capabilities fused with human analysis also allows clients to gain real-time cyber threat intel and help build better and stronger resilience to cyber breaches and hacks. Due to the nature of the collected data, the company also offer threat intelligence capabilities out-of-box to their subscribers.

THIS POST HAS BEEN EXPORTED FROM OUR MEDIUM CHANNEL

Disclaimer: This blog is based on our research and the information available at the time of writing. It is for informational purposes only and does not constitute legal, financial, or professional advice. While we strive for accuracy, we do not guarantee the completeness or reliability of the content. If any sensitive information has been inadvertently included, please contact us for correction. Cyble is not responsible for any errors, omissions, or decisions made based on this content. Readers should verify findings and seek expert advice where necessary. All trademarks, logos, and third-party content belong to their respective owners and do not imply endorsement or affiliation. All content is presented “as is” without any guarantee that it is free of confidential, proprietary, or otherwise sensitive information. If you believe any portion of this content contains inadvertently shared or sensitive data, please contact us immediately so that we may address and rectify the issue. No Liability for Errors or Omissions Due to the dynamic nature of cyber threat activity, this [blog/report/article] may include partial, outdated, or otherwise incorrect information due to unverified sources, evolving security threats, or human error. We expressly disclaim any liability for errors or omissions or any potential consequences arising from the use, misuse, or reliance on this information.

Get Threat Assessment Report

Identify External Threats Targeting Your Business​
Free
CISO's Guide to Threat Intelligence 2024

CISO’s Guide to Threat Intelligence 2024: Best Practices

Stay Ahead of Cyber Threats with Expert Insights and Strategies. Download Free E-Book Now

Stay informed

Subscribe to Cyble

Get the latest threat intelligence, research, and security updates straight to your inbox.

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Share the Post:
Scroll to Top

Book your session

Request a Personalized Demo

See how Cyble's threat intelligence protects your organization. A specialist will reach out within one business day.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams

Download the brochure

Get the Cyble Vision Brochure

Explore how Cyble Vision delivers AI-powered threat intelligence across your attack surface. Fill in your details to access the brochure.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams