Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the accelerated-mobile-pages domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Deprecated: Optional parameter $options declared before required parameter $ad is implicitly treated as a required parameter in /www/cisomagcom_810/public/wp-content/plugins/advanced-ads/classes/display-conditions.php on line 208

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the easy-digital-downloads domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the edd_cfm domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the edds domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the edd-recurring domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Deprecated: Optional parameter $params declared before required parameter $secretWord is implicitly treated as a required parameter in /www/cisomagcom_810/public/wp-content/plugins/edd-2checkout/sdk/lib/Twocheckout/TwocheckoutReturn.php on line 6

Deprecated: Optional parameter $insMessage declared before required parameter $secretWord is implicitly treated as a required parameter in /www/cisomagcom_810/public/wp-content/plugins/edd-2checkout/sdk/lib/Twocheckout/TwocheckoutNotification.php on line 6

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the edd-recurring domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the Newsmag domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /www/cisomagcom_810/public/wp-includes/functions.php on line 6121

Warning: Cannot modify header information - headers already sent by (output started at /www/cisomagcom_810/public/wp-includes/functions.php:6121) in /www/cisomagcom_810/public/wp-content/themes/Newsmag/functions.php on line 616

Warning: Cannot modify header information - headers already sent by (output started at /www/cisomagcom_810/public/wp-includes/functions.php:6121) in /www/cisomagcom_810/public/wp-includes/feed-rss2.php on line 8
e-learning platform Archives - CISO MAG | Cyber Security Magazine Beyond Cyber Security Thu, 01 Oct 2020 17:34:18 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.1 Data Breach Affected 2Mn Users of Indian E-Learning Platform Edureka https://staging-cisomagcom.kinsta.cloud/data-breach-affected-2mn-users-of-indian-e-learning-platform-edureka/ Fri, 02 Oct 2020 04:04:49 +0000 https://staging-cisomagcom.kinsta.cloud/?p=7192 Security researchers from SafetyDetectives discovered an unsecured Elasticsearch server belonging to an Indian e-learning platform Edureka, which exposed the personal information of around 2 million users. The researchers stated that the server was left online without password protection, allowing open access to the information in it. The researchers found the vulnerability on August 1, 2020, […]

The post Data Breach Affected 2Mn Users of Indian E-Learning Platform Edureka appeared first on CISO MAG | Cyber Security Magazine.

]]>
Security researchers from SafetyDetectives discovered an unsecured Elasticsearch server belonging to an Indian e-learning platform Edureka, which exposed the personal information of around 2 million users. The researchers stated that the server was left online without password protection, allowing open access to the information in it.

The researchers found the vulnerability on August 1, 2020, with prominent security flaws. The leaky database was secured after SafetyDetectives reported the issue to the Indian Computer Emergency Response Team (CERT-In). The server, located in the U.S. and hosted by AWS, exposed more than 45 million records totaling to 27 gigabytes, including first names, email addresses, phone numbers, country of residence, login activity records, Auth token information, and courses/information users had accessed previously.

The Breach Impact

The data breach could impact users if the exposed information falls into the wrong hands. Cybercriminals could exploit the stolen personal information to launch various socially engineered attacks and phishing scams.

“Users’ contact details could be harnessed to conduct a wide variety of scams while personal information from the leak could be used to encourage click-throughs and malware downloads. Personal information is also used by hackers to build up rapport and trust, with a view of carrying out a larger magnitude intrusion in the future. With access to highly sensitive information, Edureka’s compromised server security could have been devastating to entire organizations such as other universities, companies, or government departments,” SafetyDetectives said.

E-Learning Platforms @ Risk

There has been a surge in the usage of online learning platforms during the ongoing pandemic. In the recent past, hackers targeted multiple e-learning portals to steal users’ personal information. India-based online learning platform Unacademy also suffered a data breach that exposed details of 22 million users. Cybersecurity firm Cyble revealed that the unknown hackers kept 21,909,707 user records for sale at $2,000 on darknet forums. The compromised information included usernames, hashed passwords, date of joining, last login date, account status, email addresses, first and last names, and other account profile details. Earlier, a Spanish e-Learning platform 8Belts suffered a data breach that exposed personal data of over 100,000 e-learners across the globe.

The post Data Breach Affected 2Mn Users of Indian E-Learning Platform Edureka appeared first on CISO MAG | Cyber Security Magazine.

]]>
Data Breach Affects PII of 1 Mn OneClass App Users Across North America https://staging-cisomagcom.kinsta.cloud/oneclass-app-data-breach/ Tue, 30 Jun 2020 09:00:59 +0000 https://staging-cisomagcom.kinsta.cloud/?p=6193 OneClass app, a Canada-based online learning platform, suffered a data breach after an unsecured Elasticsearch database exposed personal information of over 1 million students across North America. Security researchers at vpnMentor discovered the leaky database sized over 27GB that contained PII and educational data of the students. The researchers detected the data breach on May […]

The post Data Breach Affects PII of 1 Mn OneClass App Users Across North America appeared first on CISO MAG | Cyber Security Magazine.

]]>
OneClass app, a Canada-based online learning platform, suffered a data breach after an unsecured Elasticsearch database exposed personal information of over 1 million students across North America. Security researchers at vpnMentor discovered the leaky database sized over 27GB that contained PII and educational data of the students. The researchers detected the data breach on May 20, 2020 and reported it to OneClass authorities. The database is now secured.

“By not securing its users’ data, OneClass has created a goldmine for criminal hackers, jeopardizing the privacy and security of over a million young people and their families,” the researchers said in a statement.

The exposed information included full names, schools and universities attended, email addresses, phone numbers, school and university course enrollment details and OneClass account details. It is estimated that around 8,972,251 student records may have been exposed in the data breach.

“OneClass users are very young – including minors – and will generally be unaware of most criminal schemes and frauds online. This makes them particularly vulnerable targets. It is also likely many of them use their parent’s credit cards to sign up, exposing their whole family to risk. It is also possible that some of the data belongs to minors, as OneClass includes resources for high school students and accepts users from 13 years old and above. Many records also included additional information on individual students and their courses, including faculty details and access to otherwise protected textbooks and question and answer exercises,” researchers added.

Cyberattacks on E-Learning Platforms

There has been a  surge in the usage of online learning platforms during the ongoing pandemic. Hackers targeted multiple e-learning portals to steal users’ personal information. In a  similar incident, India-based online learning platform Unacademy suffered a data breach that exposed details of 22 million users. Cybersecurity firm Cyble revealed that the unknown hackers kept 21,909,707 user records for sale at $2,000 on darknet forums. The compromised information included usernames, hashed passwords, date of joining, last login date, account status, email addresses, first and last names, and other account profile details. Earlier, a Spanish e-Learning platform 8Belts suffered a data breach that exposed personal data of over 100,000 e-learners across the globe. According to an investigation report, the 8Belts database was stored on a misconfigured Amazon Web Services (AWS) S3 bucket which resulted in the data leakage.

 

The post Data Breach Affects PII of 1 Mn OneClass App Users Across North America appeared first on CISO MAG | Cyber Security Magazine.

]]>