Unpatched BlueKeep flaw exposed law firm’s CISO password during test
A law firm’s chief information security officer’s password was exposed during a penetration test after the tester exploited an unpatched Windows flaw to access the firm’s systems. The incident showed how neglecting basic safeguards can undermine significant security spending and leave an organisation vulnerable.
The tester, Joe Brinkley, said the firm had spent about half a million dollars addressing earlier security weaknesses, yet its Windows machines remained vulnerable to BlueKeep, a flaw disclosed and exploited in 2019. He used it to access 2,500 computers and found passwords stored in plain text; one account used “r3@lg00dp@$$w0rd”, a predictable substitution for “realgoodpassword”. The account belonged to the CISO, who recognised it when the password appeared in the tester’s presentation.
- An unpatched Windows flaw gave a tester access to 2,500 computers.
- The CISO used a password stored in plain text.
- The incident highlights the need for patching, encryption and two-factor authentication.
Read the full article at the source →
Originally published by The Register as “CISO thought he had a ‘r3@lg00dp@$$w0rd’ but forgot to patch”.