News: 1689973091

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

VirusTotal: We're sorry someone fat-fingered and exposed 5,600 users

(2023/07/21)


VirusTotal today issued a mea culpa, saying a blunder earlier this week by one of its staff exposed information belonging to 5,600 customers, including the email addresses of US Cyber Command, FBI, and NSA employees.

The unintentional leak was due to the [1]layer-eight problem; human error. On June 29, an employee accidentally uploaded a .csv file of customer info to VirusTotal itself, said Emiliano Martinez, tech lead of the Google-owned malware analysis site.

"This CSV file contained limited information of our Premium account customers, specifically the names of companies, the associated VirusTotal group names, and the email addresses of group administrators," Martinez [2]wrote in a Friday disclosure.

[3]

"We removed the file, which was only accessible to partners and corporate clients, from our platform within one hour of its posting."

[4]

[5]

The employee had this list in the first place because the customer data was "critical to their role," we're told.

For those who don't know: VirusTotal allows netizens to – among other things – upload files, or submit a URL to one, and the site runs the material through various malware-scanning engines to see if anything malicious is detected or identified. Premium subscribers can also [6]download uploaded samples, and thus that's how the uploaded .csv file of customer info was accidentally leaked.

[7]

Martinez said the snafu was "unequivocally" not the result of a security breach or vulnerability: "There were no bad actors involved." After the accidental upload, VirusTotal is reexamining its processes and control processes, he said.

"Again we apologize for any confusion or concern this may have caused," Martinez concluded.

[8]JumpCloud says 'nation state' gang hit some customers

[9]North Korea created very phishy evil twin of Naver, South Korea's top portal

[10]Google changes email authentication after spoof shows a bad delivery for UPS

[11]Nickelodeon probes claims of massive data leak as SpongeBob fans rejoice

Der Spiegel first [12]reported the leak on Monday, saying the 313KB file contained users' names and email addresses belonging to organizations' employees who registered for a VirusTotal account.

This reportedly included more than 20 US Cyber Command email addresses, as well as those belonging to the US Justice Department, FBI and NSA. German, Dutch, and British and Taiwanese agencies were also affected, including Germany's federal police, Military Counterintelligence Service, as well as major German corporations like BMW, Mercedes-Benz and Deutsche Telekom. ®

Get our [13]Tech Resources



[1] https://www.theregister.com/2016/08/03/humans_always_trump_antiphishing_schemes/

[2] https://blog.virustotal.com/2023/07/apology-and-update-on-recent-accidental.html

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZLsAAxJCarbLiPg-uks5zQAAAgo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZLsAAxJCarbLiPg-uks5zQAAAgo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZLsAAxJCarbLiPg-uks5zQAAAgo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://developers.virustotal.com/reference/files-download

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZLsAAxJCarbLiPg-uks5zQAAAgo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2023/07/18/jumpcloud_commands_hacking/

[9] https://www.theregister.com/2023/06/15/north_korea_fake_naver_attack/

[10] https://www.theregister.com/2023/06/09/google_bimi_email_authentication/

[11] https://www.theregister.com/2023/07/06/nickelodeon_confirms_data_leak/

[12] https://www.spiegel.de/netzwelt/web/virustotal-datenleck-offenbart-kunden-der-google-sicherheitsplattform-a-abc16326-ddff-4a11-b149-d96be7f3bdbd?giftToken=4744d0ad-c79c-4334-90fa-3506016ec736

[13] https://whitepapers.theregister.com/



The Bulwer-Lytton fiction contest is held ever year at San Jose State
Univ. by Professor Scott Rice. It is held in memory of Edward George
Earle Bulwer-Lytton (1803-1873), a rather prolific and popular (in his
time) novelist. He is best known today for having written "The Last
Days of Pompeii."

Whenever Snoopy starts typing his novel from the top of his doghouse,
beginning "It was a dark and stormy night..." he is borrowing from Lord
Bulwer-Lytton. This was the line that opened his novel, "Paul Clifford,"
written in 1830. The full line reveals why it is so bad:

It was a dark and stormy night; the rain fell in torrents -- except
at occasional intervals, when it was checked by a violent gust of
wind which swept up the streets (for it is in London that our scene
lies), rattling along the housetops, and fiercely agitating the scanty
flame of the lamps that struggled against the darkness.