ZeroHour
CyberScooppublished ()ingested @snlyngaas

Postal Service left vulnerable IT applications unaddressed for years, inspector general finds

criticalExploit / PoC exploited in the wildimportance 60
Full article806 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The "common, well-known vulnerabilities" could have been exploited by hackers using "publicly available methods,” the report found.

The United State Postal Service headquarters in Washington, D.C.

Officials at the U.S. Postal Service let multiple vulnerable applications languish on the agency’s IT network for years — flaws that could have been exploited by hackers to steal sensitive data, an inspector general audit has found.

The inspector general investigation, distributed to Postal Service leadership in July, faults IT officials at the agency for not keeping a slew of applications up to date. Six of the IT applications were left on the Postal Service network for up to seven years with things like incomplete certification and accreditation from technology executives, according to the IG memo.

A dozen vulnerabilities were deemed “catastrophic” by the USPS’s Corporate Information Security Office, the watchdog said, meaning they could have exposed the agency to big financial damages. “These are common, well-known vulnerabilities that have been present for three years that could be exploited by an attacker utilizing publicly available methods,” the memo reads.

“The vulnerabilities identified in this report were found, scoped and addressed by the Postal Service,” an agency spokesperson told CyberScoop. “These applications are now addressed.”

But before they were addressed, the inspector general report concluded, the Postal Service “did not completely evaluate the risks these vulnerable applications posed.”

Postal Service executives agreed with the audit’s findings and pledged to improve the agency’s cybersecurity. CyberScoop has not seen any evidence that the vulnerabilities have been exploited by hackers.

Vice News was first to report on the audit.

It is unclear which IT applications the inspector general’s office studied. That information is redacted in the report.

This is not the first time the Postal Service has struggled with IT security. It took the agency more than a year to fix a vulnerability in its website that allowed anyone with a USPS account to view the personal details of 60 million other users, journalist Brian Krebs reported in November 2018. The agency said at the time there was no indication that the vulnerability had been exploited.

Perhaps the biggest confirmed breach suffered by the Postal Service took place in September 2014, when hackers infiltrated the agency’s computer systems and compromised personal data on some 800,000 employees.

UPDATE, 09/11/20, 1:46 p.m. EDTThis story has been updated with a statement from the USPS. 

More Scoops

An election worker processes mail-in ballots at the Los Angeles County Ballot Processing Center during California’s state primary election in the City of Industry, California, on June 2, 2026. Californians go to the polls Tuesday in the first round of voting for a new governor, with a tight three-way race for two run-off spots, while people in Los Angeles will also be voting for a new mayor. The state’s so-called “jungle primary” pits all comers against each other — regardless of party — with the top two vote-getters advancing to the November general election to replace term-limited Governor Gavin Newsom. (Photo by Patrick T. Fallon / AFP via Getty Images)

SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules

The 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids anything of anyone outside…

The front of the U.S. Supreme Court building is seen after sunset on June 24, 2024, in Washington, DC. (Photo by J. David Ake/Getty Images)

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

Nadezhda Buravleva, iStock/Getty Images Plus

Open-source security is posing challenges governments can’t easily solve

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/postal-service-inspector-general-cyber-vulnerabilities/