Cyber Hacking News

Uber suffers internal system breach

0

Uber suffered a cyberattack in which the hacker gained access to vulnerability reports and shared screenshots of the company’s internal systems, email dashboard, and Slack server.

According to the screenshots shared by the hacker, he seems to have full access to many critical Uber IT systems, including the company’s security software and Windows domain.

The systems accessed by the hacker also includes the company’s Amazon Web Services console, VMware ESXi virtual machines, Google Workspace email admin dashboard, and Slack server, to which the hacker posted messages.

Uber confirmed the attack and stated that they have contacted law enforcement.

The New York Times which reported the breach first said that they have spoken to the threat actor, who said they breached Uber after performing a social engineering attack on an employee and stealing their password.

The threat actor then gained access to the company’s internal systems using the stolen credentials.

The threat actor stole data and source code from Uber during this attack, but they also managed to get access to the company’s HackerOne bug bounty program, where they commented on all of the company’s bug bounty tickets.

Uber runs a HackerOne bug bounty program that allows security researchers to privately disclose vulnerabilities in their systems and apps in exchange for a bug bounty reward. These vulnerability reports are meant to be kept confidential until a fix can be released to prevent attackers from exploiting them in attacks.

According to sources, the attacker downloaded all vulnerability reports before they lost access to Uber’s bug bounty program. This likely includes vulnerability reports that have not been fixed, posing a severe security risk to Uber.

HackerOne has since disabled the Uber bug bounty program, cutting off access to the disclosed vulnerabilities.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Chinese hackers use new Linux version of the SideWalk Backdoor

Previous article

Crypto Trading firm Wintermute loses $160M in DeFi hack

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *