Security News

Cybersecurity news aggregator

MEDIUM Vulnerabilities SC Media

Misconfigured Perforce servers remain widespread, threaten sensitive data exposure

  • What: Misconfigured Perforce servers pose a risk of sensitive data exposure.
  • Impact: Organizations using Perforce may have their source code and sensitive data exposed.
Read Full Article →

Data Security , Patch/Configuration Management Misconfigured Perforce servers remain widespread, threaten sensitive data exposure April 22, 2026 Share By SC Staff Improperly secured internet-exposed Perforce P4 servers continue to be prevalent, with 72% of 6,122 online instances enabling read-only source code access through a remote user account activated by default, according to SecurityWeek . At least one account with no password was observed across 21% of public servers, posing a direct read-write access risk, while 4% could be subjected to total system compromise due to an unsecured "superuser" account, a report from Australian security researcher Morgan Robertson showed. Additional findings revealed that nearly 54% of 2,826 servers that remain active at their original IP addresses permit remote user account-based read-only access to source code without any authentication. Misconfigured Perforce P4 servers were found to have been owned by a North American law enforcement software provider, a North American commercial EV startup, a global industrial automation company, a banking software manufacturer, and other major organizations. Alerts regarding such an exposure have already been provided by Robertson to Perforce and over 60 of the impacted entities. SC Staff Related Data Security Agoda refutes claims of massive data breach SC Staff April 22, 2026 Asia-centric booking platform Agoda has denied the alleged theft of 82 million records from its systems just a week after its parent firm Booking Holdings disclosed having been subjected to a Booking.com data breach that exposed user reservation details, according to Cybernews. Breach Almost 600K reportedly impacted by separate US healthcare breaches SC Staff April 22, 2026 Three healthcare providers across the U.S. were noted by the Department of Health and Human Services' breach tracker to have been impacted by separate cyberattacks last year, which have collectively compromised data from about 600,000 individuals, SecurityWeek reports. Ransomware Extensive Citizens Financial Group, Frost Bank breaches claimed by Everest ransomware SC Staff April 22, 2026 Cybernews reports that major U.S. banks Citizens Financial Group and Frost Bank were allegedly compromised by the Everest ransomware-as-a-service operation, which has threatened to expose troves of data pilfered from both financial institutions by Apr. 26. Related Events Cybercast Beyond the Hype: The Cybersecurity Trends CISOs are Keeping an Eye on in 2026 On-Demand Event Cybercast Beyond the data perimeter: Why next-generation DSPM is the foundation for modern data security On-Demand Event Virtual Conference Securing the Future of Finance: Strategies to Counter Modern Cyber Threats On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bit Bug Ciphertext Cryptographic Hash Functions Cyclic Redundancy Check (CRC) Data Encryption Standard (DES) Diffie-Hellman Digital Envelope Digital Signature Disassembly You can skip this ad in 5 seconds

Share this article