Categories: Overall

Whistleblower claims Ubiquiti covered up a massive security breach

Ubiquiti, a company whose prosumer-grader-grader-grade routers have become synonymous with security and manageability. After 24 hours of silence, the company has now issued a statement that does n’t deny any of the whistleblower’s claims.

Ubiquiti emailed its customers about a’minor security breach’ at a’third party cloud provider’ on January 11th. A whistleblower from the company who spoke to Krebs claimed that Ubiquiti itself was breached, and that the company’s legal team prevented efforts to accurately report the dangers to customers.

Hackers got full access to the company’s AWS servers. Ubiquiti allegedly left root administrator logins in an LastPass account.

‘they were able to get cryptographic secrets for single sign-on cookies and remote access, full source code control contents, and signing keys exfiltration,’ the source said.

Ubiquiti issued a statement this evening saying it had no evidence to indicate that any user data had been accessed or stolen. But the whistleblower explicitly stated that the company does n’t keep logs, which would act as that evidence, on who did or did n’t access the hacked servers. The hacker did try to extort it for money, but does n’t address the allegations of a cover up.

We were the victim of a cybersecurity incident that involved unauthorized access to our it systems. We would like to give our community with more information.

The attacker was locked out of our systems on January 11, July 11. The incident occurred during an analysis of customer data and the security of our products.

The attacker tried to extort the company by threatening to release stolen source code and specific it credentials. This, along with other evidence, is why we believe that customer data was not the target of, or otherwise accessed in connection with, the incident.

We have well-developed evidence that the perpetrator is an individual with intricate knowledge of our cloud infrastructure. We still encourage you to change your password if you have not already done so, including on any website where you use the same user ID or password.

Ubiquiti admits its own it systems were accessed. But it does n’t address much else. The statement confirms some of what the whistleblower said.

The company’s networking gear promises full control over your home or small business network, without the fears of cloud-based solutions.

Spread the AI news in the universe!
Nuked

Recent Posts

Half-Life: Alyx at All-Time Low Price – A Must-Have for VR Owners!

Hello, my fellow tech enthusiasts! Today, I want to talk to you about a fantastic…

2 hours ago

Creating PDFs on the Go: A Guide for iPhone Users

Hello, my tech-savvy followers! Today, let's talk about how to create PDFs on your iPhones…

2 hours ago

Nike’s Adapt BB Sneakers: Losing Control with App Removal

Hey there, my fellow tech-loving pals! It's your funny guy Nuked here with some news…

1 day ago

Score a Deal: Amazon’s Fire HD 10 Tablet on Sale for Prime Members

Hello, my followers! Today, let's talk about a great deal for all the tech lovers…

1 day ago

Kindle Crisis Averted: Amazon Resolves Book Download Outage

Hello my fellow tech enthusiasts! Today I bring you some news about Amazon Kindle book…

1 day ago

Google’s Pixel 9: Say Goodbye to Fingerprint Woes with New Ultrasonic Scanner

Hello my followers! Today we have some exciting news about Google's upcoming Pixel 9 lineup.…

1 day ago