From DailyTech: Security firm Kaspersky Security has been left embarrassed after a hacker informed them that a customer information database was left exposed for 11 days before the security firm was able to secure it.
"Honestly, this is not good for any company and especially not good for a company dealing with security," Kaspersky senior antivirus researcher Roel Schouwenberg said during a media phone conference. "This should not have happened. We are now doing everything within our power to do the forensics on the case, and to prevent this from happening again."
Although no customer information was reportedly accessed by the intruder, the millions of customers who have used Kaspersky may think twice before doing so again. In total, 2,500 users' e-mail addresses and around 25,000 product activation codes were at risk over the 11-day period.
A posting on the Hackersblog.org web site includes screenshots of the hacker who used an SQL injection to access the company's database. It looks like a part of Kaspersky's U.S. support site was breached using the SQL injection attack -- the site was created an unnamed third party and was not reviewed properly by the security company prior to being used on the site.
View: Article @ Source Site