This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

KBA 135412 - GDPR

Hi,

 

Is anyone else reporting this to the authorities under GDPR as a data breach?

 

Just wondering what next steps for others are.

 

Thanks



This thread was automatically locked due to age.
Parents
  • It should be reported by Sophos themselves (although others can also report it).

    To be fair, aside from the vulnerability itself, the seem to have handled it well so far. What the report doesn't have details of, is what the SQL injection vulnerability was. SQL injections are a known issue so I wonder why the OS didn't filter this one out.

  • Hi All,

    Please reference the following Sophos Uncut article for more info: https://news.sophos.com/en-us/2020/04/26/asnarok/

    Data exfiltration process

    • Note: This section describes our understanding of the data exfiltration capabilities of the malware at the time of publication of this article, but we have not discovered any evidence that the data collected had been successfully exfiltrated.
Reply Children
No Data