Cisco jobs portal exposed personal data

By
Follow google news

Error in security settings.

Wrongly configured security settings in a Cisco portal used for job applications has resulted in the leak of personal data online.

Cisco jobs portal exposed personal data

The networking vendor told affected individuals that a "limited set of job application related information" had been exposed due to botched settings in the mobile version of its professional careers website.

It said the issue arose after an "incorrect security setting" was made following system maintenance. The settings were in place from August to September 2015 and July to August this year.

Cisco said data leaked included names, physical and email addresses, education and work history, cover letters, resumes, passwords and phone numbers, and potentially gender, race, and disability information.

It claimed there was no evidence of unauthorised access other than by the unidentified security researcher who reported the leak, but admitted it had discovered an "instance of unexplained, anomalous connection to the server" during the months the incorrect settings were in place.

Cisco said [pdf] it had immediately corrected the settings and reset user passwords upon discovering the leak.

It is advising applicants to change their login credentials and responses to security questions if they have reused the details on other sites. 

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

ASD to critical infrastructure ops: be ready to isolate systems for three months

ASD to critical infrastructure ops: be ready to isolate systems for three months

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week

Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week

OpenAI's Hugging Face hack mixed technical brilliance with incoherent noise

OpenAI's Hugging Face hack mixed technical brilliance with incoherent noise

Log In

  |  Forgot your password?