Law firm insisted on one password to rule them all
ID: dd3dbc43-7555-53bc-a0e8-368135f7a3bb
STIX ID: report--dd3dbc43-7555-53bc-a0e8-368135f7a3bb
Feed Name: The Register (Security)
This PWNED column describes a law firm that relied on a single master admin password which allowed staff to impersonate any user (staff or client) by supplying an email address, exposing sensitive client information including health records. The firm's IT employee refused to implement a backdoor, but management mitigated the issue by indiscriminately promoting all users to system admin rather than fixing authentication and access controls, leaving significant privacy and security risks despite no reported exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
