The Dell API Breach: It could have been prevented
ID: 2edfc1bb-b0a7-5f48-a123-15a020d89451
STIX ID: report--2edfc1bb-b0a7-5f48-a123-15a020d89451
Feed Name: Security Boulevard
The report reviews an incident where an attacker created a partner account and exploited a Dell partner-facing API and business-logic weakness to enumerate and harvest 49 million customer records by sending thousands of randomized seven-character service-tag queries per minute. The theft was enabled by lack of partner vetting, absent rate limiting and API monitoring; the report uses the case to illustrate API protection gaps and recommends using Salt's behavioral/ML-based API defense to detect and prevent similar scraping attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
