UPDATED 22:32 EDT / NOVEMBER 28 2017

CLOUD

Top-secret spy data exposed on misconfigured Amazon cloud instance

Top-secret data belonging to the United States Army Intelligence and Security Command, a joint U.S. Army and National Security Agency Defense Department command that gathers intelligence data, has been found exposed and open to the public.

It was yet another case of a misconfigured Amazon Web Services S3 storage instance. The discovery was made by Chris Vickery, director of cyber risk research at UpGuard Inc., who detailed in a blog post that the exposed S3 instance he stumbled upon in late September.

It included more than  100 gigabytes of data, including details of the top-secret Distributed Common Ground System-Army, an intelligence distribution platform that includes a cloud-based spying program called “Red Disk.”

Red Disk is said to have been developed to deliver intelligence to troops with tablets and laptop computers on the ground in Afghanistan via the cloud but was never fully deployed.

Other data found in the AWS S3 instance included an Open Virtual Appliance file, which contained a virtual hard drive and configuration data for a Linux-based virtual machine that could have been used by hackers to obtain access to the Pentagon. “While the virtual OS and HD can be browsed in their functional states, most of the data cannot be accessed without connecting to Pentagon systems—an intrusion that malicious actors could have attempted had they found this bucket,” Vickery said.

The exposure of the data on a misconfigured S3 instance is not the first time a company or organization has managed to expose private data to the public and it likely won’t be the last. Previous examples of private data being exposed to the public on AWS include Accenture Plc.Verizon Communications Inc. and the U.S. military contractor TigerSwan. Amazon itself announced earlier this month a range of security features to prevent these “misconfigurations” occurring in the future.

Those “misconfigurations” ultimately occurred due to inept staff and a failure of those utilizing AWS to secure the data they uploaded. Carl Wright, chief revenue officer at AttackIQ Inc., told SiliconANGLE that more needs to be done at an enterprise level.

“Over the past month we have seen a number of enterprise organizations fail because they inadvertently did not configure existing security controls properly,” Wright said. “This is called a protection failure and indicates that these organizations are doing little to no testing to validate that existing security controls are working properly.”

“The cost to validate your security controls is comparably infinitesimal compared to the cost of a data breach,” Wright added. “It is a disturbing state of IT and security management when the attackers are routinely able to find protection failures before corporate or government security teams.”

Photo: rudiriet/Flickr

A message from John Furrier, co-founder of SiliconANGLE:

Support our open free content by sharing and engaging with our content and community.

Join theCUBE Alumni Trust Network

Where Technology Leaders Connect, Share Intelligence & Create Opportunities

11.4k+  
CUBE Alumni Network
C-level and Technical
Domain Experts
15M+ 
theCUBE
Viewers
Connect with 11,413+ industry leaders from our network of tech and business leaders forming a unique trusted network effect.

SiliconANGLE Media is a recognized leader in digital media innovation serving innovative audiences and brands, bringing together cutting-edge technology, influential content, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — such as those established in Silicon Valley and the New York Stock Exchange (NYSE) — SiliconANGLE Media operates at the intersection of media, technology, and AI. .

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a powerful ecosystem of industry-leading digital media brands, with a reach of 15+ million elite tech professionals. The company’s new, proprietary theCUBE AI Video cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.