Urgent.News

What's breaking now, across thousands of outlets.

Tech

CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch

Replacing letters with symbols still doesn’t make it good.

CISO thought he had a 'r3@lg00dp@$$w0rd' but forgot to patch

In a recent incident reported by "The Blind Hacker," Joe Brinkley, it was discovered that a high-ranking official at a law firm had a weak security practice. Despite spending nearly half a million dollars on security software following a previous audit, the company failed to patch its Windows machines against BlueKeep, a critical remote code execution vulnerability discovered in 2019.

BlueKeep affects numerous versions of Windows, including Windows 2000, Windows Server 2008 R2, and Windows 7, and can spread from one system to another due to its wormable nature. The security lapse extended to the storage of passwords in plain text, which were easily extracted by Brinkley. The usernames were cleverly designed to mask privileges, while the password for the high-ranking official, Yellow Banana, was laughably simple: "r3@lg00dp@$$w0rd."

Brinkley shared a screenshot of this password with the firm's executives during a presentation on system vulnerabilities. The CISO, who identified as Yellow Banana, was understandably embarrassed when he learned of the password's exposure. Experts advise that organizations should promptly patch their systems and avoid using simple, easy-to-guess passwords.

Implementing two-factor authentication and encrypting passwords could also significantly enhance security.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

More from Thursday 1 October →