Click2Gov Breaches Attributed to WebLogic Application Flaw

  /     /     /  
Publicated : 22/11/2024   Category : security


Click2Gov Breaches Attributed to WebLogic Application Flaw


At least 10 US cities running Click2Gov software have alerted citizens to a data breach, but it turns out the problem was in the application server.



A discovery has been made regarding a series of security incidents in US cities using an online billing software called Click2Gov. Over the past year, at least 10 cities running the software have alerted citizens to data breaches. It turns out Click2Govs program wasnt being attacked.
Risk Based Securitys Inga Goddijn
noticed a pattern
of Click2Gov, a product of Superion Software, appearing in breach notification letters. The notifications came from cities across the United States, which reported both data breaches and the installation of cryptocurrency miners. Oxnard, Calif. was most recently breached; its incident occurred on May 25.
Further investigation by Superion showed the attackers didnt break in through Click2Gov but through third-party software needed to use it: Oracles WebLogic application server. The WebLogic vulnerability has been patched and since the crux of the problem is not within Click2Gov, cities running the cloud-based version of the software have not been affected, according to a Codebook report.
Read more details
here
.
Why Cybercriminals Attack: A DARK READING VIRTUAL EVENT Wednesday, June 27. Industry experts will offer a range of information and insight on who the bad guys are – and why they might be targeting your enterprise. Go
here
for more information on this free event.

Last News

▸ Some DLP Products Vulnerable to Security Holes ◂
Discovered: 23/12/2024
Category: security

▸ Scan suggests Heartbleed patches may not have been successful. ◂
Discovered: 23/12/2024
Category: security

▸ IoT Devices on Average Have 25 Vulnerabilities ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
Click2Gov Breaches Attributed to WebLogic Application Flaw