Hackers drain Bitcoin ATMs of $1.5M by exploiting 0-day bug
arstechnica.com
arstechnica.com
Let's publish names of the audit providers. Let's fix the industry of sloppy audits just "for compliance". Let's blame them as well, as they certified it's secure.
However, just because they've had multiple security audits, doesn't mean those audits didn't find issues that weren't dealt with.
"multiple security audits" as you know, means hardly anything.
Also, if it is a zero day bug, then potentially the audit may not have ever picked it up.
In my own experience I've noticed that a lot of times it's really hard to get the clients to address these sorts of issues, even when it's clear that they are critical and could directly translate to monetary loses which makes no sense to me but sadly doesn't surprise me at all.
Just to be clear, of course there is a scope and a web service audit doesn't usually end up with a thorough audit of all the packages used by the application because nobody will pay for that and even if they would, it's usually mind numbing enough to end up in people glancing over things and checking boxes but in most cases this is not the root of the issue.