ZeroHour

Search: “customer data”

2,858 items

Test environment let anyone access live customer datanew

A security audit found an internet-exposed staging environment connected to live customer data, lacking production-grade authentication and access controls.

The Register's PWNED column recounts how Richard Schut, now of SmartRepl, discovered during a pre-cloud-migration audit that a mid-size company's test environment was externally accessible and wired to a database with live customer information. The staging instance, created for a short-term demo and migration testing, remained running for six months without production authentication. Access was restricted after discovery and the team reviewed all other test environments.

AWS Says Some Cloud Data Cannot Be Recovered After Data Centers Suffer War Damagenew

AWS confirmed some customer data in war-damaged Middle East data centers is permanently unrecoverable after Iranian drone strikes hit Bahrain and UAE facilities.

Amazon Web Services said in a September 15 Health Dashboard update that it is unable to restore data hosted exclusively in its Bahrain me-south-1 region and the UAE mec1-az2 availability zone after Iranian missile and drone strikes that began in March. Damage in Bahrain spanned multiple availability zones, exceeding what AWS regional and multi-AZ services are designed to withstand. Customers without backups outside the affected footprint lost data permanently; AWS has suspended regional billing, notified authorities in both countries, and expects further UAE updates in coming months and Bahrain updates in early 2027.

Cyber Security News · 41m agoIndustry

Shadow AI in Financial Services | Risk & Governance

Huntress warns financial services firms that unsanctioned 'Shadow AI' tool use creates data leakage and compliance risks faster than governance controls can keep pace.

Huntress argues Shadow AI — employee use of unapproved AI tools such as ChatGPT and Microsoft Copilot — is spreading across financial services faster than visibility and controls. Uploading regulated customer data into public generative models risks breaches of client confidentiality, data protection rules, and market conduct obligations. The piece recommends secure web gateways, DNS filtering, DLP, application allowlisting, and corporate SSO/MFA for approved tools rather than outright bans, which can push usage onto personal devices.

Huntress · 13d agoIndustry