Security firm Carbon Black awoke to a damning report Wednesday morning about a severe flaw in one of its top software products: Sensitive corporate data from some major companies -- clients of Carbon Black -- have been found on multi-scanner services.
The report from DirectDefense, a managed security strategies provider, ties the data leak to an API key that the company claims belongs to Carbon Black Cb Response, a next-generation anti-malware endpoint detection and response tool.
Cb Response is responsible for leaking hundreds of thousands of files comprising terabytes of data, according to the report.
[Join Your Peers at HIMSS Healthcare Security Forum! Register Today]
Researchers sampled 100 files and identified leaks in several major companies, including: a large streaming media company, a social media company and a financial services business.
The leak contains a wide range of company data: cloud keys, single sign-on passwords, two-factors keys, customer data, proprietary internal applications like custom algorithms and trade secrets, app store keys, internal usernames, passwords and network intelligence and customer data.
DirectDefense left impacted company names out of the report to protect identities. However, the researchers did contact all customers found on the database.
The leaked data exist primarily around various executable formats (we havent seen evidence of this in documents or pdfs yet), the report authors wrote. However, if handled incorrectly, even executables can easily contain serious data leakage of information that can be hazardous to a companys security posture.
Carbon Black provides security tools to a wide range of companies, almost 2,000 customers globally -- including those in the healthcare industry.
The issue stems from data collected about potential threats that are aggregated into a central location to be later analyzed by researchers. Carbon Black separates the good files from the bad files to prevent harmful files from running.
However, it relies on whitelisting to ward off threats -- forcing Carbon Black to continuously analyze a rapidly increasing pool of data. DirectDefense researchers said the issue is when the security firm encounters new files from clients and is unsure of whether a file is good or bad -- it sends the file to a secondary cloud-based multi-scanner to be scored.
Translation: All new files from clients are uploaded to Carbon Black at least once. The result of gaining access to the multiscanner would allow a hacker to also gain access to the files submitted to the database.
Welcome to the worlds largest pay-for-play data exfiltration botnet, the report authors wrote.
And to make matters worse, the report wasnt able to definitively conclude whether this flaw is specific to Carbon Black. What the researchers do know is that Carbon Blacks prevalence in the marketspace and the design of their solutions architecture seems to be providing a significant amount in data exfiltration.
Carbon Black customers should review the data being collected through the Cb Response product and evaluate the type of data that exists on the network. Those concerned about third-party access, like healthcare organizations, could also utilize disabling cloud uploads. But keep in mind that it will negatively impact security, as new files cant be scored.
In a blog post, Carbon Black Co-founder and CTO Michael Viscuso said: Theres an optional, customer-controlled configuration (disabled by default) that allows the uploading of binaries (executables) to VirusTotal for additional threat analysis.
This option can be enabled by a customer, on a per-sensor group basis, he continued. When enabled, executable files will be uploaded to VirusTotal, a public repository and scanning service owned by Google. We appreciate the work of the security research community.
Carbon Black was not informed about the issue brought to light by DirectDefense before it was published. Specifically, Viscuso explained that DirectDefense asserts that this an architectural flaw in all Cb products.
But this is exclusively a Cb Response feature not included in Cb Protection or Cb Defense, said Viscuso. Its also not a foundational architectural flaw. Its a feature, off by default, with many options to ensure privacy and a detailed warning before enabling."
This post was updated to include comments from Carbon Black CTOMichael Viscuso.
Twitter:@JessieFDavis Email the writer: jessica.davis@himssmedia.com
Like Healthcare IT News on Facebook and LinkedIn
More here:
Carbon Black may be leaking terabytes of customer data (UPDATED) - Healthcare IT News
- Mind uploading won't lead to immortality - Life 2.0 ... [Last Updated On: June 10th, 2016] [Originally Added On: June 10th, 2016]
- Mind uploading won't lead to immortality - Life 2.0 ... [Last Updated On: June 12th, 2016] [Originally Added On: June 12th, 2016]
- Mind uploading in fiction - Wikipedia, the free encyclopedia [Last Updated On: June 12th, 2016] [Originally Added On: June 12th, 2016]
- Mind Uploading [Last Updated On: June 21st, 2016] [Originally Added On: June 21st, 2016]
- Trasferimento della mente - Wikipedia [Last Updated On: June 28th, 2016] [Originally Added On: June 28th, 2016]
- Mind Uploading FAQs [Last Updated On: June 30th, 2016] [Originally Added On: June 30th, 2016]
- Mind uploading - RationalWiki [Last Updated On: June 30th, 2016] [Originally Added On: June 30th, 2016]
- Brain Uploading - TV Tropes [Last Updated On: July 1st, 2016] [Originally Added On: July 1st, 2016]
- Carboncopies.org Foundation [Last Updated On: July 1st, 2016] [Originally Added On: July 1st, 2016]
- The History of SIM, Whole Brain Emulation and Mind Uploading [Last Updated On: July 31st, 2016] [Originally Added On: July 31st, 2016]
- What are the Benefits of Mind Uploading? - Lifeboat [Last Updated On: November 12th, 2016] [Originally Added On: November 12th, 2016]
- 2100 Technology | Timeline | 22nd Century | Future ... [Last Updated On: November 21st, 2016] [Originally Added On: November 21st, 2016]
- Unsterblichkeit Wikipedia [Last Updated On: November 23rd, 2016] [Originally Added On: November 23rd, 2016]
- Mind uploading - Transhumanism Wiki - Wikia [Last Updated On: December 2nd, 2016] [Originally Added On: December 2nd, 2016]
- Make Money from Images, Documents and Photos Uploading [Last Updated On: December 7th, 2016] [Originally Added On: December 7th, 2016]
- Immortal but Damned to Hell on Earth - The Atlantic [Last Updated On: January 29th, 2017] [Originally Added On: January 29th, 2017]
- Faultlines, black holes and glaciers: mapping uncharted territories - The Guardian [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How to keep your children safe online as it's revealed half of six-year-olds use the internet - Mirror.co.uk [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Yetunde Olasiyan: Between Having a Voice & the Need to Show Off on Social Media - Bella Naija [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How a WiFi Pilot Program Is Helping Students in the Rio Grande Valley - Texas Public Radio [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Looking for a New Job? 4 Ways to Job Search Discreetly - U.S. News & World Report (blog) [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Khloe Kardashian narrowly avoids a wardrobe malfunction in sexy underwear photo - OK! Magazine [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- How a WiFi Pilot Program Is Helping Students in the Rio Grande Valley - KWBU [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Connectivity in a digital world - Iowa City Press Citizen [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Does Your Vision for Your Life Cause You to Look Up...or Down? - Huffington Post [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- How to improve your LinkedIn profile - ArabianBusiness.com [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- How a WiFi Pilot Program Is Helping Students in the Rio Grande Valley - KUT [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Deal: New customers can get Google Play Music and YouTube Red free for 4 months - Android Authority (blog) [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Procurious and SOPO Launch Innovative Online Community Platform for Government Procurement Professionals - PR Newswire UK (press release) [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Breaking Down Global Silos (Part 2): Lessons Learned from Conflict - Spend Matters [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Robbie Williams' wife Ayda proves she's the best ever as she completely overshares with hilarious birthday card to him - The Sun [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Morality and Murder Collide in Two New Horror Movies - Film School Rejects [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Jefferson schools urged to use cable TV station - Daily Union [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Olly Murs sings Happy Birthday to Robbie Williams with full backing band in sweet video - The Sun [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Eric Adler Is Living The Dream With The New England Patriots - Cape Cod Chronicle [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Squash review: Drop and compress your way to smaller image files in a flash - Macworld [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- It's time to get tech-savvy with The Mind Lab by Unitec! - Scoop.co.nz [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Tennyson soundtracks movies for your mind with Like What - Straight.com [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Fake news, who benefits? - Shelbyville Times-Gazette (blog) [Last Updated On: February 17th, 2017] [Originally Added On: February 17th, 2017]
- Crazy Videos on YouTube That No One Can Explain - Thrillist [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- Barbie becomes a hologram version of herself - TechCrunch [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- The Owl at the Window review: They the living - Irish Times [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- Tax Software: The Basics Work, but Peace of Mind Costs Extra - New York Times [Last Updated On: February 18th, 2017] [Originally Added On: February 18th, 2017]
- How To Run A Rogue Government Twitter Account With An Anonymous Email Address And A Burner Phone - UPROXX [Last Updated On: February 20th, 2017] [Originally Added On: February 20th, 2017]
- The three reasons YouTubers keep imploding, from a YouTuber - Polygon [Last Updated On: February 22nd, 2017] [Originally Added On: February 22nd, 2017]
- SnailBlitz 2017: Citizen Scientists Wanted - NBC Southern California [Last Updated On: February 22nd, 2017] [Originally Added On: February 22nd, 2017]
- Breakdown In Immigration Screening: The Devil Is In The Details - Daily Caller [Last Updated On: February 22nd, 2017] [Originally Added On: February 22nd, 2017]
- Appealing Social Security Decisions Online - Danbury News Times [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- Nikon D5600 Review: Hoping to Make Photo Transfers a Snap - Huffington Post [Last Updated On: February 26th, 2017] [Originally Added On: February 26th, 2017]
- How to file your social security appeal online - KARE [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- Comparison: 3 Platforms Paying You in Bitcoin for Uploading Images - Nigeria Today [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- How to file your social security appeal online - WZZM13.com [Last Updated On: February 28th, 2017] [Originally Added On: February 28th, 2017]
- How To File Your Social Security Appeal Online - WFMYNews2.com [Last Updated On: March 1st, 2017] [Originally Added On: March 1st, 2017]
- B2B processes get smarter in the cloud - TechTarget [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Data limits are the worsthere's how to stay under yours - Popular Science [Last Updated On: March 2nd, 2017] [Originally Added On: March 2nd, 2017]
- Overcome problems with public cloud storage providers - TechTarget [Last Updated On: March 4th, 2017] [Originally Added On: March 4th, 2017]
- From AI to Anxiety Relief, The Brain Needs a Body - Big Think [Last Updated On: March 4th, 2017] [Originally Added On: March 4th, 2017]
- The Modest Problem of Death: On Mark O'Connell's To Be a Machine - lareviewofbooks [Last Updated On: March 4th, 2017] [Originally Added On: March 4th, 2017]
- Mind the gap: burn and destroy mission in Bengal fields leaves a few questions - Hindustan Times [Last Updated On: March 5th, 2017] [Originally Added On: March 5th, 2017]
- A man with vitiligo who was called 'zebra' by bullies has defied their cruel comments by becoming a model - The Sun [Last Updated On: March 8th, 2017] [Originally Added On: March 8th, 2017]
- Cam Site Launches iTunes-Like Marketplace Of Oral Sex For Women - AskMen [Last Updated On: March 10th, 2017] [Originally Added On: March 10th, 2017]
- Everything new in Stellaris: Utopia, one of Paradox's biggest game ... - PC Gamer [Last Updated On: March 10th, 2017] [Originally Added On: March 10th, 2017]
- Paytm to continue free uploading of money - Business Standard [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- Paytm to continue free uploading of money | Free Press Journal - Free Press Journal [Last Updated On: March 11th, 2017] [Originally Added On: March 11th, 2017]
- How to upload photos to Instagram from a PC: Upload your favourite images to Instagram on Windows 10 without a ... - PC Advisor [Last Updated On: March 17th, 2017] [Originally Added On: March 17th, 2017]
- 2017 Foresight Fellows Announced in Molecular Machines, Space, Longevity, Artificial Intelligence - Benzinga [Last Updated On: March 17th, 2017] [Originally Added On: March 17th, 2017]
- Best Practices for 2017 SEO Audits [PODCAST] - Search Engine Journal [Last Updated On: March 23rd, 2017] [Originally Added On: March 23rd, 2017]
- Science to Beat the Death: 200 300 years old human in the Future! - Sri Lanka Guardian [Last Updated On: March 23rd, 2017] [Originally Added On: March 23rd, 2017]
- Microsoft's Windows 10 Creators Update lives up to its name - Engadget [Last Updated On: March 29th, 2017] [Originally Added On: March 29th, 2017]
- Film reviews: Ghost In The Shell and other releases - Herald Scotland [Last Updated On: April 2nd, 2017] [Originally Added On: April 2nd, 2017]
- Death of a Dystopian - The New Yorker [Last Updated On: April 3rd, 2017] [Originally Added On: April 3rd, 2017]
- Stealth Rick and Morty premiere a delightful surprise - Marquette Wire [Last Updated On: April 3rd, 2017] [Originally Added On: April 3rd, 2017]
- Severe Weather Risk on Wednesday - WEAR [Last Updated On: April 5th, 2017] [Originally Added On: April 5th, 2017]
- Showtime docu-series sees the 'Dark' side of tech - LA Daily News [Last Updated On: April 5th, 2017] [Originally Added On: April 5th, 2017]
- Report It - Maui Now [Last Updated On: April 7th, 2017] [Originally Added On: April 7th, 2017]
- The perils and false rewards of parenting in the era of 'digi-discipline' - Minnesota Public Radio News [Last Updated On: April 7th, 2017] [Originally Added On: April 7th, 2017]
- Elon Musk: Australian man pens desperate letter to download his brain - NEWS.com.au [Last Updated On: April 7th, 2017] [Originally Added On: April 7th, 2017]
- Police body cameras part of Dothan's new integrated system - Dothan Eagle [Last Updated On: April 10th, 2017] [Originally Added On: April 10th, 2017]
- This Is the Dawn of Brain Tech, But How Far Can It Go? - Singularity Hub [Last Updated On: April 12th, 2017] [Originally Added On: April 12th, 2017]
- 7 easy ways to make your iPhone videos look pro - CNET [Last Updated On: April 13th, 2017] [Originally Added On: April 13th, 2017]