The Bug that caused the Equifax Breach was just two months old

“Equifax has been deeply examining the scope of the interference with the support of a leading, independent cyber security firm to discover what information was obtained and who have been impacted,” company executives wrote in an update posted online. “We understand that offenders exploited a US website employment vulnerability. The vulnerability was Apache Struts CVE-2017-5638. We remain to work with law requirement as part of our illegal investigation, and have experienced indicators of agreement with law enforcement.”

Take your time to comment on this article.

Related posts

Sweet Security Brings Autonomous Protection to the AI Enterprise with New Blocking Capabilities

Public Exploit Lands for vBulletin’s Pre-Auth RCE, CVE-2026-61511

Insignary Closes SBOM Accuracy Gap With Binary-Level Clarity for Regulatory Risk