CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch
Replacing letters with symbols still doesn’t make it good.
In a recent case of security negligence, a chief information security officer (CISO) at a law firm failed to patch critical vulnerabilities on his company's Windows systems. The security breach was compounded by the use of a weak, easily guessable password. The CISO, who is also known as "The Blind Hacker," was contracted by a national law firm to perform a penetration test on one of its subsidiaries before a merger and acquisition.
During the test, he discovered numerous security holes and a particularly egregious password used by the CISO himself. The password, "r3@lg00dp@$$w0rd," was a hashed version of "realgoodpassword" with random symbols and numbers. The CISO's password was stored in plain text, making it easily accessible to anyone who gained access to the system.
The CISO was unable to explain his reasoning behind choosing such a weak password, which ultimately led to his identity being revealed during the presentation to the law firm's executives. The incident serves as a stark reminder of the importance of regularly patching systems and using strong, unique passwords.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch theregister.com