Hi,
Is anyone else reporting this to the authorities under GDPR as a data breach?
Just wondering what next steps for others are.
Thanks
This thread was automatically locked due to age.
Hi,
Is anyone else reporting this to the authorities under GDPR as a data breach?
Just wondering what next steps for others are.
Thanks
It should be reported by Sophos themselves (although others can also report it).
To be fair, aside from the vulnerability itself, the seem to have handled it well so far. What the report doesn't have details of, is what the SQL injection vulnerability was. SQL injections are a known issue so I wonder why the OS didn't filter this one out.
Hi All,
Please reference the following Sophos Uncut article for more info: https://news.sophos.com/en-us/2020/04/26/asnarok/
Data exfiltration process
Hi All,
Please reference the following Sophos Uncut article for more info: https://news.sophos.com/en-us/2020/04/26/asnarok/
Data exfiltration process