The Bug that caused the Equifax Breach was just two months old

“Equifax has been deeply examining the scope of the interference with the support of a leading, independent cyber security firm to discover what information was obtained and who have been impacted,” company executives wrote in an update posted online. “We understand that offenders exploited a US website employment vulnerability. The vulnerability was Apache Struts CVE-2017-5638. We remain to work with law requirement as part of our illegal investigation, and have experienced indicators of agreement with law enforcement.”

Take your time to comment on this article.

Related posts

SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise

Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional Pentests

Lunar Cyber Launches Token Exposure Monitoring as Infostealers Target Developer and AI Credentials