sb-as logo
Story image

Google Groups users unwittingly leaking information: Change sharing settings now

25 Jul 2017

Google has been the focus of two major security warnings this week, one of which exposes a major hole in Google Groups file privacy.

Security firm RedLock detected a major misconfiguration in Google Groups, which publicly exposed sensitive details from hundreds of groups.

When using Google Groups, changing the sharing option for ‘Outside this domain – access to groups’, which allows users to make files public or private. A handful of major companies chose to make some information ‘public on the internet’, inadvertently exposing sensitive information to anyone who uses the internet.

Those groups include an online weather company, a cloud-based helpdesk provider and a video advertising platform.

RedLock is urging all Google Groups users to set the sharing for “Outside this domain – access to groups” to ‘private’.

RedLock CEO and co-founder Varun Badhwar says that simple configuration errors, even in cloud applications such as Google, can have serious effects.

“In today’s environment, it’s imperative that every organization take steps to educate employees on security best practices and leverage tools that can automate the process of securing applications, workloads and other systems. In the cloud, for example, a resource only exists for 127 minutes on average – there’s no way for IT teams alone to keep up with this rapid rate of change,” Badhwar says.

Meanwhile, Google has also fixed a problem with its name spoofing vulnerability. Researchers at Proofpoint discovered vulnerabilities that could allow attackers to bypass Google controls in apps.

Google introduced controls after the OAuth worm, however attackers could potentially launch a repeat of that attack.

“If exploited, the name spoofing vulnerability would have been harder to detect and stop than the original May 2017 attack, which tricked users into authorizing illegitimate Google docs applications and collected/targeted their email contacts,” comments Proofpoint vice president of threat operations, Kevin Epstein.

Proofpoint recommends that users take the following precautions when installing apps:

  • Verify the authenticity of the app’s developer including whitelisting apps for your enterprise.
  • Understand what the app is doing before you install it.
  • If you installed a suspect, unverified app, revoke permission via https://myaccount.google.com/permissions?pli=1

Proofpoint says that Google has now remediated the issue, but caution is still advised.

“Securing third-party applications is extremely important as more and more organizations rely on cloud-based solutions to conduct operations worldwide,” Epstein concludes.

Story image
BlueVoyant acquires Managed Sentinel, builds out Microsoft MSS offerings
“Combining Managed Sentinel’s Azure Sentinel deployment expertise with BlueVoyant’s MDR capabilities will help customers operationalise and maximise Microsoft security technologies."More
Story image
Insider threat report reveals deception in the workforce
Insider threats come from people inside an enterprise, whether they divulge proprietary information with nefarious intentions, or are just careless employees that unwittingly share sensitive data, writes Bitglass product marketing manager Juan Lugo.More
Story image
Microsoft takes legal action to disrupt botnet and combat ransomware
Microsoft has announced it took action to disrupt a botnet, Trickbot, one of the world's most infamous botnets and prolific distributors of malware and ransomware.More
Story image
Secureworks: Remote working exposes new security vulnerabilities
New vulnerabilities have been exposed as IT teams across the world respond to the ongoing COVID-19 pandemic.More
Story image
Why organisations should wise up to the DDoS extortion trend
While it is essential to have a DDoS mitigation solution in place, it’s also important to test that it works as expected, writes NCC Group director of technical security consulting for Asia Pacific Tim Dillon.More
Story image
Gartner reveals the top strategic tech trends for 2021
“CIOs are striving to adapt to changing conditions to compose the future business - this requires the organisational plasticity to form and reform dynamically. Gartner’s top strategic technology trends for 2021 enable that plasticity.”More