<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Responding to the Capital One security breach?</title><link>https://community.sophos.com/utm-firewall/f/web-server-security/114465/responding-to-the-capital-one-security-breach</link><description>According to KrebsOnSecurity.com (8/2/2019 blog post), the massive Capital One security breach started with a misconfigured WAF site running ModSecurity, which was running on Amazon Web Services. My summary of his report: 
 
 An AWS employee exploited</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Responding to the Capital One security breach?</title><link>https://community.sophos.com/thread/411465?ContentTypeID=1</link><pubDate>Thu, 08 Aug 2019 19:07:31 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:0e279b8a-a0a4-4b46-a9a4-e80a728c9cc3</guid><dc:creator>DouglasFoster</dc:creator><description>&lt;p&gt;I try to avoid including non-Sophos links in my posts, partly as a courtesy and partly because I thought the moderation rules restricted doing so.&amp;nbsp; &amp;nbsp; Based on some of the spam entries I have encountered, it appears that such a restriction is not actually in place, but perhaps badly needed.&amp;nbsp; &amp;nbsp;However, since you asked, this is the link to the full article.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://krebsonsecurity.com/2019/08/what-we-can-learn-from-the-capital-one-hack/#more-48424"&gt;https://krebsonsecurity.com/2019/08/what-we-can-learn-from-the-capital-one-hack/#more-48424&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I read Krebs intermittently, but I have found his blog to be well informed.&amp;nbsp; &amp;nbsp;The website has ads, but I have not detected threat content in any of the ads.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Responding to the Capital One security breach?</title><link>https://community.sophos.com/thread/411292?ContentTypeID=1</link><pubDate>Wed, 07 Aug 2019 03:15:53 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:bd44e4f2-af61-479f-a90b-c4c93b56d489</guid><dc:creator>Jaydeep</dc:creator><description>&lt;p&gt;Hi &lt;a href="/members/douglasfoster"&gt;DouglasFoster&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Do you have the link of that article? For any official word or guide, you would require to create a case with &lt;a href="https://secure2.sophos.com/en-us/support/open-a-support-case.aspx" target="_blank"&gt;Sophos Support&lt;/a&gt; and get that information.&amp;nbsp;I will check with our team and see if there&amp;#39;s anything we need to take care of in regards to this issue.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>