<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Data Breach on Rietta Cybersecurity</title>
    <link>https://rietta.com/tags/data-breach/</link>
    <description>Recent content in Data Breach on Rietta Cybersecurity</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <copyright>1999-2026 Rietta Inc. All Rights Reserved.</copyright>
    <atom:link href="https://rietta.com/tags/data-breach/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Equifax Missed Defense in Depth, Allowing a Massive Data Breach</title>
      <link>https://rietta.com/blog/equifax-defense-in-depth/</link>
      <pubDate>Mon, 18 Sep 2017 00:00:00 -0400</pubDate>
      <guid>https://rietta.com/blog/equifax-defense-in-depth/</guid>
      <description>&lt;p&gt;Equifax has confirmed that the main vector that lead to the data breach was a remote code execution vulnerability in Apache Struts that had been known for months [&lt;a href=&#34;https://rietta.com/blog/equifax-defense-in-depth/#equifax-announcement&#34;&gt;1&lt;/a&gt;]. Equifax had not yet patched it within the production environment. This is not just a lesson in the importance of patch management but one of defense in depth. The weakness in Equifax&amp;rsquo;s design was set in motion years before when they failed to design with the assumption that the front-end web server would be compromised.&lt;/p&gt;&#xA;&lt;p&gt;The attacker was able to obtain the massive trove of private data because the web application was the only gatekeeper. Once the remote code execution vulnerability was exploited, the attacker was able to access data unfettered by additional access controls.  Equifax chose to use a typical web application architecture without defense in depth.&lt;/p&gt;&#xA;&lt;p&gt;Defense in depth has to start as part of the development process. All developers should be aware of the OWASP Top 10 (&lt;a href=&#34;https://rietta.com/blog/equifax-defense-in-depth/#owasp-top10&#34;&gt;#3&lt;/a&gt;) and their work should be audited against the OWASP Advanced Security Verification Standard (ASVS) [&lt;a href=&#34;https://rietta.com/blog/equifax-defense-in-depth/#owasp-asvs&#34;&gt;#3&lt;/a&gt;] for the level appropriate for the risk faced by an organization in the event of a security breach.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
