Tesla, VW data was left exposed by supply chain vendor Level One Robotics
Tesla, VW, and dozens of other manufacturers had their sensitive information exposed due to a weak security link in their supply chains. The exposure occurred at industrial automation provider Level One Robotics via an inadequately secured rsync file transfer protocol server, according to researchers at UpGuard Cyber Risk. The researchers found the server wasn't restricted meaning clients connected to it could access the data and with the right knowledge of where trade secrets were stored could pilfer them. In addition, "the permissions set on the rsync server at the time of the discovery indicated that the server was publicly writable, meaning that someone could potentially have altered the documents there, for example replacing bank account numbers in direct deposit instructions or embedding malware," a situation, UpGuard researchers wrote in a blog post, that poses a "significant risk." Researchers couldn't determine whether miscreants had accesse...