Then again I didn't expect much, their MSSQL in prod had SA/SA credentials active.
Then again I didn't expect much, their MSSQL in prod had SA/SA credentials active.
A few brave companies have tried to put their FTP systems behind VPNs, but the momentum is hard to overcome. What is more popular is firewall rules that only allow large blocks of IPs owned by other vendors they deal with. It is good in theory, until you see how large/diverse some of these blocks are (e.g. all of AWS's Eastern data center).
It was a very loud wake-up call seeing what inter-business stuff looked like. It is the wild west or a flashback to the 1990s security wise.
On HIPAA PHI.
(I know HIPAA doesn't actually mandate 2FA, but it's recommended by many best practices and guides.)
Apparently some tech folks don't like the inconvenience of 2FA.
https://duo.com/blog/federal-contractors-must-meet-cybersecu...
Many of the recent attacks I've seen simply bypass it altogether in favor of phishing or other traditional techniques.
Clients (Ansible?) simply don't work with it or do it well, which leads to hacks that undermine your 2FA deployment anyway-- rogue admins opening reverse tunnels to allow file transfers, webshells, etc.
EDIT: Oh, and the network controllers that ran them were uniformly updated and managed with fully open "admin" username no-password telnet and ftp services. IoT insecurity began a looooong time before the term IoT even existed.