• About
  • Advertise
  • Careers
  • Contact
Friday, March 31, 2023
No Result
View All Result
NEWSLETTER
Cyber360 News
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us
No Result
View All Result
Cyber360 News
No Result
View All Result
Home Data Breach

Cyber experts say advice from breached IoT device company Ubiquiti falls short

by Cyber360 News
January 13, 2021
in Data Breach
0
Cyber experts say advice from breached IoT device company Ubiquiti falls short
0
SHARES
10
VIEWS
Share on FacebookShare on Twitter
A Ubiquiti NanoStation Wireless Bridge seen in operation. Ubiquiti experienced a breach that may have exposed customer data. (KN6KS/CC BY-NC 2.0)

IoT networking device vendor Ubiquiti experienced a breach of a web portal it uses to manage remote devices and as a support portal.

The web servers stored information pertaining to user profiles for the account.ui.com portal that Ubiquiti makes available to customers who bought one of its router or webcam products, a ZDNet report said.

The company said in a statement it only recently became aware of the breach. And while there’s no evidence of access to any databases that host user data, Ubiquiti is not certain whether the breach exposed user data, such as names, addresses, phone numbers, email addresses and one-way encrypted passwords to user accounts.

As a precaution, Ubiquiti said, users should change their passwords on the company’s web portal and on any website where they may have used the same user ID or password. Ubiquiti also recommend that users enable two-factor authentication on all accounts they have with the company.

But advising customers to rotate passwords, including any other internet services where the same passwords have been used, is a common poor practice that often results in data breaches escalating further, according to Joseph Carson, chief security scientist and advisory chief information security officer at Thycotic. 

“The response has been mixed as the notification did not provide much detail on what a good password is, or advice on using a password manager to help increase the security of such privileged access,” Carson said. “The scary thought is whether or not this unauthorized access has allowed attackers access to customer’s networks, including security camera footage. Companies such as Ubiquiti that focus on access and security should demand multi-factor authentication by default and integrate into password management security solutions, as this breach shows the importance of not letting a password be your only security control.”

With the passwords to IoT devices and the system to manage them, Craig Lurey, co-founder and chief technology officer of Keeper Security, said cybercriminals could take a number of malicious actions, including:

  • Logging into the IoT devices and use them to launch a DDoS attack.
  • Logging into the IoT devices and use them for real-world crimes. For example, access to webcams can be used for cyberspying/cyberstalking, and bad actors can access smartlocks to conduct burglaries.
  • Using the stolen passwords in brute-force attacks on other websites. Password reuse is common, and in fact, in its email, Ubiquiti instructed customers to reset passwords that they’re reusing elsewhere.

Topics:

Breach
IoT

Cyber360 News

Cyber360 News

Next Post
Microsoft Patch Tuesday for January 2021 fixes 83 flaws, including an actively exploited issue

Microsoft Patch Tuesday for January 2021 fixes 83 flaws, including an actively exploited issue

Recent Posts

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

Twitch’s Entire Critical Data Leaked, Includes Streamer Earnings, Source Code

October 6, 2021
Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

Former U.S. Security Firm Helped The UAE Carry Out “Karma” iMessage Hack: MIT Tech Review

October 1, 2021
Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

Facing “This App Has Been Blocked For Your Protection” Issue? Here’s How You Can Fix It

October 1, 2021

Whats New in Kali Linux?

September 14, 2021

Kali Linux 2019.3 Release (CloudFlare, Kali-status, metapackages, Helper-Scripts & LXD)

September 14, 2021

Kali Linux 2021.3 Release (OpenSSL, Kali-Tools, Kali Live VM Support, Kali NetHunter Smartwatch)

September 14, 2021

Kali Linux 2018.4 Release

September 14, 2021

Kali Linux 1.0.5 and Software Defined Radio

September 14, 2021

Kali Tools Website Launched, 1.0.9 Release

September 14, 2021

Kali Linux Dojo at Black Hat Vegas 2016

September 14, 2021

Category

Site Links

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

About Us

We bring you the best Premium WordPress Themes that perfect for news, magazine, personal blog, etc. Check our landing page for details.

© 2019 Cyber360 News - Powered by WebSensePro

No Result
View All Result
  • Home
  • Security
  • Data Breach
  • Cyber Attacks
  • Cyber Security
  • Cyber Crime
  • Contact Us

© 2019 Cyber360 News - Powered by WebSensePro

Login to your account below

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In