• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 25, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Data Leak
  • UpGuard: 50.4 GB of data was leaked due to unprotected Amazon Web Services
  • Data Leak

UpGuard: 50.4 GB of data was leaked due to unprotected Amazon Web Services

Ddos March 11, 2018 3 minutes read

The cloud security vendor UpGuard’s cyber risk team discovered a group of 50.4 GB of data leaked due to unprotected Amazon Web Services (AWS) S3 buckets.

This 50.4 GB data relates to Birst’s main customer, Capital One, a financial services giant based in McLean, Virginia and also the eighth largest commercial bank in the United States. It includes Capital One network infrastructure configuration information and Birst’s equipment technology information.

According to an official blog post issued by UpGuard, this data contains passwords, management access credentials, and private keys, and is used exclusively by Capital One’s related systems in Birst’s internal cloud environment. The attackers used this leaked data to grasp Capital One’s use of Birst equipment, and then invade the IT system and dig deeper into the company’s internal information.

By Amazon.com Inc. (Amazon) [Apache License 2.0], via Wikimedia Commons

On January 15, 2018, Chris Vickery, director of online risk research at UpGuard, discovered the leaked data. The data was located in the “capitalone-appliance” subdomain and allowed access by any user.

They found that one of the files was marked as “Client.key” and contained the encryption key used to decrypt the data. This method of storing the key with the encryption device is the same as leaving the key and the lock in a public place. The hacker can use this to easily decrypt the encrypted device. The leaked data also included the username and hashed password used by Birst, and the incident completely revealed how the Birst device was constructed. The attackers will be able to focus on invading Capital One and another More extensive system. The most noteworthy of these is the number of business intelligence dashboards used to connect Birst devices and other service port locations.

When cryptocurrency prevails, public AWS buckets can now also be used for cryptocurrency mining. Recently, Tesla’s Amazon account was hacked and used to conduct Monroe mining. The incident also revealed Tesla’s incident in storing sensitive data in Amazon S3 buckets.

In addition, on February 24, 2018, researchers also discovered an Amazon S3 bucket belonging to the Los Angeles Times. The hackers exploited the configuration error of the bucket to mine Monroe Coin through CoinHive’s JavaScript code. With the help of this code, hackers were able to use the computer resources of visitors to the Los Angeles Times website to mine.

UpGuard currently removes blog posts about Birst’s database breach. In addition, banking giant Capital One also denied this data breach.

Source: upguard

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Top 8 biggest hacks of 2017
  2. US secret military base is revealed due to tracking sports Strava application
  3. Hacker group stole the credentials of over 71,000 Nvidia employees
  4. Dropbox security incident: hackers accessed to 130 GitHub source code repositories
  5. Microsoft PlayReady DRM Certificates Leaked: SL3000 Pulled from GitHub, Amazon Suspends Pirate Accounts
Tags: UpGuard

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-9478CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the...
  • CVE-2026-9477CVSS 9.8
    A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue...
  • CVE-2026-9476CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the...
  • CVE-2026-9475CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function...
  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
  • CVE-2026-9454CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects...
  • CVE-2026-9436CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.