Security firm Carbon Black awoke to a damning report Wednesday morning about a severe flaw in one of its top software products: Sensitive corporate data from some major companies -- clients of Carbon Black -- have been found on multi-scanner services.
The report from DirectDefense, a managed security strategies provider, ties the data leak to an API key that the company claims belongs to Carbon Black Cb Response, a next-generation anti-malware endpoint detection and response tool.
Cb Response is responsible for leaking hundreds of thousands of files comprising terabytes of data, according to the report.
[Join Your Peers at HIMSS Healthcare Security Forum! Register Today]
Researchers sampled 100 files and identified leaks in several major companies, including: a large streaming media company, a social media company and a financial services business.
The leak contains a wide range of company data: cloud keys, single sign-on passwords, two-factors keys, customer data, proprietary internal applications like custom algorithms and trade secrets, app store keys, internal usernames, passwords and network intelligence and customer data.
DirectDefense left impacted company names out of the report to protect identities. However, the researchers did contact all customers found on the database.
The leaked data exist primarily around various executable formats (we havent seen evidence of this in documents or pdfs yet), the report authors wrote. However, if handled incorrectly, even executables can easily contain serious data leakage of information that can be hazardous to a companys security posture.
Carbon Black provides security tools to a wide range of companies, almost 2,000 customers globally -- including those in the healthcare industry.
The issue stems from data collected about potential threats that are aggregated into a central location to be later analyzed by researchers. Carbon Black separates the good files from the bad files to prevent harmful files from running.
However, it relies on whitelisting to ward off threats -- forcing Carbon Black to continuously analyze a rapidly increasing pool of data. DirectDefense researchers said the issue is when the security firm encounters new files from clients and is unsure of whether a file is good or bad -- it sends the file to a secondary cloud-based multi-scanner to be scored.
Translation: All new files from clients are uploaded to Carbon Black at least once. The result of gaining access to the multiscanner would allow a hacker to also gain access to the files submitted to the database.
Welcome to the worlds largest pay-for-play data exfiltration botnet, the report authors wrote.
And to make matters worse, the report wasnt able to definitively conclude whether this flaw is specific to Carbon Black. What the researchers do know is that Carbon Blacks prevalence in the marketspace and the design of their solutions architecture seems to be providing a significant amount in data exfiltration.
Carbon Black customers should review the data being collected through the Cb Response product and evaluate the type of data that exists on the network. Those concerned about third-party access, like healthcare organizations, could also utilize disabling cloud uploads. But keep in mind that it will negatively impact security, as new files cant be scored.
In a blog post, Carbon Black Co-founder and CTO Michael Viscuso said: Theres an optional, customer-controlled configuration (disabled by default) that allows the uploading of binaries (executables) to VirusTotal for additional threat analysis.
This option can be enabled by a customer, on a per-sensor group basis, he continued. When enabled, executable files will be uploaded to VirusTotal, a public repository and scanning service owned by Google. We appreciate the work of the security research community.
Carbon Black was not informed about the issue brought to light by DirectDefense before it was published. Specifically, Viscuso explained that DirectDefense asserts that this an architectural flaw in all Cb products.
But this is exclusively a Cb Response feature not included in Cb Protection or Cb Defense, said Viscuso. Its also not a foundational architectural flaw. Its a feature, off by default, with many options to ensure privacy and a detailed warning before enabling."
This post was updated to include comments from Carbon Black CTOMichael Viscuso.
Twitter:@JessieFDavis Email the writer: jessica.davis@himssmedia.com
Like Healthcare IT News on Facebook and LinkedIn
Read more from the original source:
Carbon Black may be leaking terabytes of customer data (UPDATED) - Healthcare IT News
- Make Money from Images, Documents and Photos Uploading [Last Updated On: December 18th, 2016] [Originally Added On: December 18th, 2016]
- Immortal but Damned to Hell on Earth - The Atlantic [Last Updated On: January 29th, 2017] [Originally Added On: January 29th, 2017]
- Hands on review: Zencastr podcast maker - The Sydney Morning Herald [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How to keep your children safe online as it's revealed half of six-year-olds use the internet - Mirror.co.uk [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Yetunde Olasiyan: Between Having a Voice & the Need to Show Off on Social Media - Bella Naija [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How a WiFi Pilot Program Is Helping Students in the Rio Grande Valley - KUT [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- These Shows Understand Why TV Cannot Survive Without The Internet And They're Doing Something About It - Decider [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- 10 reasons to not miss John Bender at El Club this weekend - Detroit Metro Times [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- Ideal Flatmate promises to stamp out all roommate worries - The Tech Portal [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- Five ways to ensure your kids are safe as they go 'online' - The Standard (press release) [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- How to improve your LinkedIn profile - ArabianBusiness.com [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Deal: New customers can get Google Play Music and YouTube Red free for 4 months - Android Authority (blog) [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Breaking Down Global Silos (Part 2): Lessons Learned from Conflict - Spend Matters [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Issa Rae New Series Giants Is A Must Watch - CampusLATELY (blog) [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Fake news, who benefits? - Shelbyville Times-Gazette (blog) [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]
- GST beneficial for traders, says official - The Hindu [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]
- It's time to get tech-savvy with The Mind Lab by Unitec! - Scoop.co.nz [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]
- 'Being an Irish author is more of a Grimm fairytale than a Cinderella story' - Irish Times [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- Barbie becomes a hologram version of herself - TechCrunch [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- PLYMOUTH BUSINESS EXPANSION: MycomPETibility.com goes nationwide - Wicked Local Kingston [Last Updated On: February 20th, 2017] [Originally Added On: February 20th, 2017]
- The three reasons YouTubers keep imploding, from a YouTuber - Polygon [Last Updated On: February 22nd, 2017] [Originally Added On: February 22nd, 2017]
- SnailBlitz 2017: Citizen Scientists Wanted - NBC Southern California [Last Updated On: February 22nd, 2017] [Originally Added On: February 22nd, 2017]
- Nikon D5600 Review: Hoping to Make Photo Transfers a Snap - Huffington Post [Last Updated On: February 27th, 2017] [Originally Added On: February 27th, 2017]
- Appealing Social Security Decisions Online - CBN News [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- How to file your social security appeal online - WZZM13.com [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Meteor is OpenSignal's own speed test app - SlashGear [Last Updated On: March 1st, 2017] [Originally Added On: March 1st, 2017]
- Data limits are the worsthere's how to stay under yours - Popular Science [Last Updated On: March 3rd, 2017] [Originally Added On: March 3rd, 2017]
- Overcome problems with public cloud storage providers - TechTarget [Last Updated On: March 3rd, 2017] [Originally Added On: March 3rd, 2017]
- When Words Beget Blows - Outlook India [Last Updated On: March 4th, 2017] [Originally Added On: March 4th, 2017]
- A man with vitiligo who was called 'zebra' by bullies has defied their cruel comments by becoming a model - The Sun [Last Updated On: March 8th, 2017] [Originally Added On: March 8th, 2017]
- Shark Tank's Robert Herjavec coaches kids to fuel entrepreneurial spirit - VentureBeat [Last Updated On: March 9th, 2017] [Originally Added On: March 9th, 2017]
- Everything new in Stellaris: Utopia, one of Paradox's biggest game updates ever - PC Gamer [Last Updated On: March 10th, 2017] [Originally Added On: March 10th, 2017]
- IN TRANSIT: The Idol Maker - Mumbai Mirror [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Paytm to continue free uploading of money - Business Standard [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- The perils and false rewards of parenting in the era of 'digi-discipline' - Minnesota Public Radio News [Last Updated On: April 8th, 2017] [Originally Added On: April 8th, 2017]
- Showtime docu-series sees the 'Dark' side of tech - LA Daily News [Last Updated On: April 8th, 2017] [Originally Added On: April 8th, 2017]
- Elon Musk: Australian man pens desperate letter to download his brain - NEWS.com.au [Last Updated On: April 8th, 2017] [Originally Added On: April 8th, 2017]
- How Vestas Wind Systems used outsourced machine learning to transform contract management - Diginomica [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Wednesday Web Artist of the Week: Eva Papamargariti - ArtSlant [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Your Obsolete Brain: Life and Death in the Age of Superintelligent Machines - Digital Journal [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- Under Armour launches its first customisable shoes - just-style.com (subscription) [Last Updated On: June 8th, 2017] [Originally Added On: June 8th, 2017]
- I Don't Care What You Think, I Love My Facial Birthmark - SELF [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Cable: Where Are We Headed After This Political Meltdown? - Seeking Alpha [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Best Screen Recorders Top 10 Screen Capture Software - Gazette Review [Last Updated On: June 10th, 2017] [Originally Added On: June 10th, 2017]
- Nigeria just got a verified Twitter handle - TechCabal [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- Just keep pinning: why your business should be on Pinterest - Cambridge Network [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- Track-by-Track of Paramore's 'Riot!' Read Through Emo Teen Memories - Noisey [Last Updated On: June 13th, 2017] [Originally Added On: June 13th, 2017]
- Decision day for Go Forward Pine Bluff - Pine Bluff Commercial [Last Updated On: June 13th, 2017] [Originally Added On: June 13th, 2017]
- Addressing rape culture - News24 [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- Italy's Samantha Cristoforetti Says Being a Good Astronaut is All About Teamwork - Fortune [Last Updated On: June 16th, 2017] [Originally Added On: June 16th, 2017]
- Google Drive will soon make it easy to Backup and Sync PCs, Macs - SlashGear [Last Updated On: June 16th, 2017] [Originally Added On: June 16th, 2017]
- What's worse than getting phished? Getting phished *and* sending a selfie of your Photo ID and credit card - Graham Cluley Security News [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- Track Of The Day 16/6 - Maximillian - Clash Magazine [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- AROUND TOWN: GOP chairman questions Ossoff's London office - MDJOnline.com [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- RESEARCH & TECHNOLOGY/INNOVATION: ITS Fiber brings fast connections, data center services to local business - TCPalm [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Fiberlink Internet Packages & Prices 2017 - TechJuice (press release) (blog) [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- CS Editors: Creating Content - Security Sales & Integration [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- How to post a GIF to Facebook - Tech Advisor (registration) [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- The Living Vampire / Real Vampire FAQ (Frequently Asked Questions) - HuffPost [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Facebook Is Introducing New Tools to Protect Women in India - Fortune [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Mum drops off daughter at college then sends her hilarious texts with football team - NEWS.com.au [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Is Chrome OS right for you? A 3-question quiz to find out - Computerworld [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Facebook wants to stop creeps from downloading your profile picture - TNW [Last Updated On: June 23rd, 2017] [Originally Added On: June 23rd, 2017]
- Action and Emotion - lareviewofbooks [Last Updated On: June 26th, 2017] [Originally Added On: June 26th, 2017]
- 6 ways to be more hirable and 1 that could land a job today - Deseret News [Last Updated On: June 27th, 2017] [Originally Added On: June 27th, 2017]
- Searching for a Career? Set up a Free Profile at AutoCareCareers.org - PR Newswire (press release) [Last Updated On: June 27th, 2017] [Originally Added On: June 27th, 2017]
- Industry Job Seekers Can Set Up A Free Profile At AutoCareCareers.Org - AftermarketNews.com (AMN) [Last Updated On: June 29th, 2017] [Originally Added On: June 29th, 2017]
- Steve Mitchell The Mind of Watercolor Blog [Last Updated On: June 29th, 2017] [Originally Added On: June 29th, 2017]
- How to Upload to Google Drive - Cloudwards [Last Updated On: July 1st, 2017] [Originally Added On: July 1st, 2017]
- Stevie Ryan, YouTube personality, found dead at home - Blasting News [Last Updated On: July 4th, 2017] [Originally Added On: July 4th, 2017]
- 5 tips to a delicious food photo - Orlando Sentinel [Last Updated On: July 5th, 2017] [Originally Added On: July 5th, 2017]
- Gordon Hayward the best Jazz wing player of all time? Not what the numbers say. - SLC Dunk [Last Updated On: July 5th, 2017] [Originally Added On: July 5th, 2017]
- 36 Years of Loretta's - Racer X Online [Last Updated On: July 6th, 2017] [Originally Added On: July 6th, 2017]
- How to Work on Your Laptop at a Coffee Shop Without Being a Jerk - Lifehacker [Last Updated On: July 8th, 2017] [Originally Added On: July 8th, 2017]
- There's a new most-viewed Youtube video, pushing Gangnam Style off the top spot - Buzz.ie [Last Updated On: July 12th, 2017] [Originally Added On: July 12th, 2017]
- How to prevent bandwidth throttling with a VPN - T3 [Last Updated On: July 14th, 2017] [Originally Added On: July 14th, 2017]
- Google will now let you back up your entire computer for FREE on its servers - Mirror.co.uk [Last Updated On: July 15th, 2017] [Originally Added On: July 15th, 2017]
- Google Drive Backup and Sync lets you backup your entire computer: Here's how it works - BGR India [Last Updated On: July 17th, 2017] [Originally Added On: July 17th, 2017]
- Why Mythology Still Matters: Wisdom from Game of Thrones' 'Dragonstone' - Big Think [Last Updated On: July 17th, 2017] [Originally Added On: July 17th, 2017]
- Mum somehow manages to convince her daughter her nipple's fallen off in hilarious text exchange - Metro [Last Updated On: July 18th, 2017] [Originally Added On: July 18th, 2017]