@cR0w@infosec.exchange Lost count of the amount of times I told a company about an exposed endpoint they had no idea they even owned. Sometimes it took months for them to even get access to it and fix the issue 😂
Leaks, leaks everywhere.
Posts
@giaco@geraffel.social @masek@infosec.exchange
Their reply to the report was asking for my full dox basically, I also followed up either way with more information and got ignored :blobshrug:
@cR0w@infosec.exchange @reverseics@infosec.exchange
I would add to be aware of the tricks and bullshit this companies try to pull in regards to disclosures too.
I had a company try to add me to a private, invite only, no disclosure VDP for simply filling a form in their website.
Edit: This billion dollar company has a paid bug bounty program, but the form in their website linked to something else instead though :)
https://jltee.substack.com/p/risk-a-ban-by-alerting-100000-people
I received an email earlier this week from EA asking if I wanted to be added to a public acknowledgement page they were creating for individuals who responsibly disclosed vulnerabilities to them.
For all the shit people give EA, of the 100+ companies I contacted in the last two years, they were the only company I would say had a decent incident response.
They fixed the issue within 12 hours after validating it as critical, and proactively provided me multiple updates over time.
When the IR was done on their side, they reached out again with some more information about the potential impact if the issue hadn't been solved quickly, and also offered me a reward.
I did not have to keep chasing anyone for updates, I wasn't asked for non-disclosure, or offered money in exchange for it, and people replied instead of ignoring me.
I wasn't blamed for their mistake, either, or reported to the authorities.
Unfortunately, at least one or multiple of the things mentioned above are present in most of my other incidents reported; it's a real shit show out there.
#cybersecurity #infosec #responsibledisclosure #vulnerability #ea #electronicarts
Cybernews made a post about a "record-breaking data breach", one they created themselves in their head.
They seem to keep updating their post with more information, and it's now a mix of false claims and contradictions.
I called @Scary@infosec.exchange and we went digging through our logs to show you just how much effort they put into researching for that article and how much of it is overblown.
https://jltee.substack.com/p/fact-checking-claims-by-cybernews
#cybersecurity #infosec #infostealer #cybernews #data #databreach #news
Without that help, it would be a way bigger challenge to get this closed, as any time I try to contact any agency or LE in the US, I just get ignored :blobshrug: