Stay updated with breaking news from Bill demirkapi. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Dell SupportAssist bugs put over 30 million PCs at risk bleepingcomputer.com - get the latest breaking news, showbiz & celebrity photos, sport news & rumours, viral videos and top stories from bleepingcomputer.com Daily Mail and Mail on Sunday newspapers.
BankInfoSecurity DougOlenick) • April 29, 2021 Get Permission Some security experts are questioning whether Experian is doing enough to ensure security after a researcher discovered that an API the credit reporting firm uses to allow lenders to check the credit score of prospective borrowers could expose customer s scores. While visiting one lender s website, Bill Demirkapi, a student at the Rochester Institute of Technology who s a threat researcher, discovered the API issue, he told Krebs on Security. The vulnerability on that website, which Experian says it has since fixed, allowed someone to look up another person s credit score and some additional financial history by inputting their name, address and date of birth. But Demirkapi says he had to enter the birthdate as all zeroes to exploit the vulnerability. ....
Researchers fear wider exposure, amidst a tepid response from Experian. A researcher is claiming that the credit scores of almost every American were exposed through an API tool used by the Experian credit bureau, that he said was left open on a lender site without even basic security protections. Experian, for its part, refuted concerns from the security community that the issue could be systemic. Join Threatpost for “Fortifying Your Business Against Ransomware, DDoS & Cryptojacking Attacks” a LIVE roundtable event on Wednesday, May 12 at 2:00 PM EDT for this FREE webinar sponsored by Zoho ManageEngine. The tool, called the Experian Connect API, allows lenders to automate FICO-score queries. Bill Demirkapi, a sophomore at Rochester Institute of Technology, was shopping for student loans when he found a lender that would check his eligibility with just a name, address and date of birth, according to a published report. ....