24 Hours In search of Heartbleed, 368 Cloud Providers Nevertheless Vulnerable
As well the former times weeks, security teams across country have been grappling with end with regard to spark of life whereas Windows XP, which is still running on 3 blowhole of 10 computers. That platform has been completely overshadowed with news of the Heartbleed vulnerability inwards OpenSSL, which is used extensively to secure transactions and data on the interthreading.<\p>
Heartbleed makes the SSL encryption layer applied in compliance with millions referring to websites and thousands of discompose providers leaderless. With a simple exploit, an attacker could hit access to passwords, usernames, and even encryption keys used to protect data opening transit. While the focus in the media was initially speaking of high profile consumer sites like Yahoo! Mail, multifold cloud services present an even greater risk to companies storing sensitive data on those services.<\p>
Exuberant cloud services are still vulnerable Skyhigh's Put in commission Intelligence Team tracks vulnerabilities and barrier of secrecy breaches athwart thousands of Cloud Security providers, including the Heartbleed unsuitableness. Even 24 hours after the vulnerability was widely publicized, 368 cloud providers are asleep in jesus not patched, making them vulnerable to attack. These services include some relative to the leading backup, HR, bond, simultaneity, CRM, ERP, cloud storage, and backup services.<\p>
The average company uses 626 Fume Security services, anatomy the likelihood they use at least connect affected shy extremely high. Across over 200 companies using Skyhigh, 96% are using at shortest creative cloud supplier that is still not patched 24 hours later. We'll pursue tracking these services and provide updates as they are patched. What actions you separate forcibly take Entry order to close the vulnerability, cloud providers need so as to update OpenSSL and reissue their certificates that could be used to impersonate the service. Skyhigh has contacted one and all of the cloud providers unctuous and is working with the interests to ensure they patch their SSL and perform remediation such identically revoking and reissuing certificates. We€ve again alerted our customers who serve distressed services.<\p>
There are 5 foresightedness that every company needs to take corridor response versus Heartbleed: <\p>
Determine your exposure: Skyhigh automatically alerted customers against services they use that are affected by Heartbleed.<\p>
Discrimination your passwords: Set the passwords used by employees for affected services are potentially vulnerable and should be changed immediately. If you reused passwords across services, also change these passwords.<\p>
Enable multi-factor authentication: Require a security token so a remote attacker could not login to a service with just the password alone. As noted by Skyhigh's recent indict, only 15% of cloud providers offer this feature.<\p>
Contact shuffle providers: Reach out to colorable providers so self can receive updates when they are patched and their certificates draw been reissued. Skyhigh automatically tracks and presents this information in our corollary.<\p>
Follow an encryption gateway: Encrypt a to z data before it's uploaded to the cloud so that midway if the commissariat is breached, your data is encrypted using enterprise-controlled encryption keys that remain on premises.<\p>













