Hackers Use Heartbleed Bug to Attack 'Major Corporation'

Catch up with NBC News Clone on today's hot topic: Hackers Use Heartbleed Bug Attack Major Corporation N84521 - Technology and Innovation | NBC News Clone. Our editorial team reformatted this story for clarity and speed.

Hackers took advantage of the Heartbleed vulnerability to break into a major corporation’s network, The New York Times reports.
Image: A lock icon, signifying an encrypted Internet connection
Researchers announced on April 7 that they have uncovered a security bug in OpenSLL dubbed Heartbleed.MAL Langsdon / Reuters

Hackers took advantage of the Heartbleed vulnerability to break into a major corporation’s network, less than a day after the bug was brought to the public’s attention, security experts told The New York Times.

Officials with Mandiant, an Alexandria, Va.-based network security firm, said in a blog post Friday that a hacker or hackers leveraged the Heartbleed bug to break into an employee’s virtual private network, or VPN.

“Once connected to the VPN, the attacker attempted to move laterally and escalate his/her privileges within the victim organization,” Mandiant said.

Image: A lock icon, signifying an encrypted Internet connection
Researchers announced on April 7 that they have uncovered a security bug in OpenSLL dubbed Heartbleed.MAL Langsdon / Reuters

Mandiant didn’t identify the company by name, but a Mandiant investigator told the Times it is a “major corporation.”

The attack occurred on April 8, just one day after the Heartbleed bug became public knowledge. Officials are still assessing what, if any, damage was caused by the hack, the Times said.

Heartbleed is a serious security flaw in OpenSSL, the software that a huge number of websites use to encrypt and transmit data. Hackers exploiting the bug can gain access to sensitive private information such as usernames and passwords.

To date, much of the discussion about Heartbleed has focused on an attacker using the vulnerability to steal private encryption keys from a Web server. The case cited by Mandiant exposed another danger: the potential for hijacking user sessions while employees are logged on to a corporate network.

The Mandiant case is one of the first known attacks involving Heartbleed. Earlier this week, Canadian police charged a 19-year-old man in connection with exploiting the bug to steal taxpayer data from a government website.

— NBC News

×
AdBlock Detected!
Please disable it to support our content.

Related Articles

Donald Trump Presidency Updates - Politics and Government | NBC News Clone | Inflation Rates 2025 Analysis - Business and Economy | NBC News Clone | Latest Vaccine Developments - Health and Medicine | NBC News Clone | Ukraine Russia Conflict Updates - World News | NBC News Clone | Openai Chatgpt News - Technology and Innovation | NBC News Clone | 2024 Paris Games Highlights - Sports and Recreation | NBC News Clone | Extreme Weather Events - Weather and Climate | NBC News Clone | Hollywood Updates - Entertainment and Celebrity | NBC News Clone | Government Transparency - Investigations and Analysis | NBC News Clone | Community Stories - Local News and Communities | NBC News Clone