Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence

Subscribe to Updates

Get the latest National Security News directly to your inbox.

What's Hot

American Man Who Joined ISIS in Syria Sentenced to 20 Years

April 2, 2023

Suella Braverman ‘committed’ to legal requirement on reporting child sex abuse

April 1, 2023

Biden admin allows immigrants to select gender identity other than birth sex after ‘Trans Day of Visibility’

April 1, 2023
Facebook Twitter Instagram
  • Privacy Policy
  • Terms and Conditions
  • Contact
Sunday, April 2
Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence
en English
en Englishet Estonianlv Latvianlt Lithuanianpl Polishro Romanianru Russianuk Ukrainian
Trending
  • American Man Who Joined ISIS in Syria Sentenced to 20 Years
  • Suella Braverman ‘committed’ to legal requirement on reporting child sex abuse
  • Biden admin allows immigrants to select gender identity other than birth sex after ‘Trans Day of Visibility’
  • Anger at government U-turn on promised ban on fur imports
  • Understanding AI Risk: I Promise This Article Wasn’t Written by ChatGPT (Yet)
  • Bill to ban TikTok slammed as ‘Patriot Act for the digital age’
  • DoD Chief Digital and Artificial Intelligence Office Launches Hack the Pentagon Website
  • Jeb Bush joins fellow GOP Trump foes in blasting Alvin Bragg’s ‘political’ indictment
Subscribe
Facebook Twitter Instagram
Estonian Free PressEstonian Free Press
Home » Cyber researcher claims a Department of Defense email server was open for the public to peruse

Cyber researcher claims a Department of Defense email server was open for the public to peruse

February 21, 20233 Mins Read United States
Share
Facebook Twitter LinkedIn Pinterest Email

Cybersecurity researcher Anurag Sen said Tuesday he discovered an exposed Department of Defense computer server containing a large trove of internal U.S. military emails.

Mr. Sen said the Microsoft Azure server contained approximately three terabytes of data, and he shared some of the information with The Washington Times, including emails involving U.S. Special Operations Command. 

Precisely who else may have had access to the data is not fully known. 

“The server … was left exposed without any authentication likely due to misconfiguration. This happens most likely due to human error,” Mr. Sen said.

The likely human error meant the server was not password protected and anyone who knew where to look would have had access after the misconfiguration occurred approximately two weeks ago, he said.

SOCOM declined to comment Tuesday and referred questions to U.S. Cyber Command, which did not immediately answer.

Mr. Sen said he discovered the problem while doing a routine check and he did not contact the U.S. government directly out of fear that it may incorrectly view him as a threat. He said he discovered the vulnerability Saturday and contacted the tech publication TechCrunch, who then alerted the U.S. government. 

Mr. Sen previously collaborated with TechCrunch Security Editor Zack Whittaker, who reported Tuesday that Mr. Sen was a “good-faith security researcher.”

Mr. Whittaker wrote that the exposed server was secured on Monday after he contacted the U.S. government on Sunday. SOCOM told TechCrunch on Tuesday morning that no one had hacked its information systems. 

Emsisoft Threat Analyst Brett Callow said server misconfigurations can enable the exposure of sensitive information that could be used for several purposes. One potential scam enabled by misconfigurations is spearphishing, which involves using electronic communications such as email to trick someone into giving improper access or sensitive information. 

Details on who was responsible for allegedly making the server vulnerable remained unclear. Microsoft did not immediately answer questions on Tuesday, including whether it bore responsibility for the exposed server. 

Problems with Microsoft’s tech previously enabled hacks from China-sponsored attackers. For example, Microsoft said in March 2021 that it observed the China-sponsored Hafnium using previously unknown exploits to attack Microsoft Exchange Server software. 

The Biden administration later identified China as the culprit behind the malicious activity against Microsoft, pointing to China’s Ministry of State Security as responsible for the cyberattacks aimed at Microsoft Exchange Server email software. The U.S. government formally attributed the attacks to China in the summer of 2021 alongside several other countries. 

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Articles Liés

Biden admin allows immigrants to select gender identity other than birth sex after ‘Trans Day of Visibility’

April 1, 2023 United States

Bill to ban TikTok slammed as ‘Patriot Act for the digital age’

April 1, 2023 United States

Jeb Bush joins fellow GOP Trump foes in blasting Alvin Bragg’s ‘political’ indictment

April 1, 2023 United States

Left-wing antisemitism and Randi Weingarten’s Jewish conspiracy theories

April 1, 2023 United States

Afghanistan haunts Biden, as it should

April 1, 2023 United States

Salvadoran national wanted in Maryland on multiple sexual assault charges apprehended at Dulles

April 1, 2023 United States
Don't Miss
United Kingdom

Suella Braverman ‘committed’ to legal requirement on reporting child sex abuse

By woe whApril 1, 20230

Sign up for the View from Westminster email for expert analysis straight to your inbox…

Biden admin allows immigrants to select gender identity other than birth sex after ‘Trans Day of Visibility’

April 1, 2023

Anger at government U-turn on promised ban on fur imports

April 1, 2023

Understanding AI Risk: I Promise This Article Wasn’t Written by ChatGPT (Yet)

April 1, 2023
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks

DoD Chief Digital and Artificial Intelligence Office Launches Hack the Pentagon Website

April 1, 2023

Jeb Bush joins fellow GOP Trump foes in blasting Alvin Bragg’s ‘political’ indictment

April 1, 2023

Using Psychology to ReSCIND Cyberattacks

April 1, 2023

Left-wing antisemitism and Randi Weingarten’s Jewish conspiracy theories

April 1, 2023

Subscribe to Updates

Get the latest National Security News directly to your inbox.

© 2023 Estonian Free Press. All rights reserved.
  • Privacy Policy
  • Terms and Conditions
  • Contact

Type above and press Enter to search. Press Esc to cancel.