Top secret Army, NSA data found on public internet due to misconfigured AWS server
Full article618 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
A misconfigured Amazon Web Services server with details on the Army's shutted 'Red Disk' project was publicly available on the open internet.
A misconfigured Amazon Web Services server operated by the U.S. Army’s Intelligence and Security Command was publicly available on the open internet, according to findings by UpGuard researcher Chris Vickery.
The hard drive’s content, which included classified material belonging to the National Security Agency, was stored on a unprotected, unlisted server, containing information about an outdated Army intelligence sharing project codenamed “Red Disk.”
Red Disk represents a defunct project that was previously spearheaded by INSCOM in order to improve one of the Army’s legacy platforms known as the distributed common ground system (DCGS). Red Disk was meant to act as a customizable cloud system for soldiers and other operators in field to access, organize and share active reports regarding military activities, including information gathering efforts.
The publicly accessible files provide an overview of how Red Disk functioned and could have been deployed. Other confidential information stored on the disk image included a mention of applications used inside Red Disk as well as a series of private keys owned by a contractor that appear to have been used by the platform in order for the database to connect to other servers on the intelligence community’s own networks.
In practice, soldiers would have been able to log into Red Disk from laptops on the battlefield to view drone footage, confidential battle reports, satellite imagery and intercepted messages from adversaries that were fed into the system by defense and intelligence collection agencies like the NSA.
Although the Pentagon spent more than $90 million on the development and implementation of Red Disk, the system was never fully deployed in the field due to technical issues that hindered the rapid sharing of information.
Users often misconfigure or simply misunderstand certain settings in AWS S3 setup, which can subsequently result in the publication of sensitive information on the public internet.
Other U.S. military and intelligence outposts — such as U.S. Central Command, U.S. Pacific Command and the National Geospatial Intelligence Agency — have made similar data storage mistakes that were also identified by Vickery. He has also found similar errors at Booz Allen Hamilton, Verizon, and Viacom.
Vickery notified the Department of Defense in October about the discovery of this open storage bucket. It’s not clear if anyone else besides Vickery accessed the files since they first came online.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/nsa-army-leak-red-disk-aws-upguard-chris-vickery/