Nextcloud Database Misconfiguration Exposes 367,000 Records Including Sensitive Client and Employee Data
Signal Watch | Nextcloud misconfiguration leaves data unprotected @channel The German modular workspace platform, Nextcloud, left a database unprotected containing 367,000 records, spilling invoices, contracts, scripts for managing infrastructure, and numerous other files. The company says no customer servers were exposed in the incident. They claim it was an error by their hosting infrastructure provider. The exposed files include sensitive data, such as Nextcloud employee data, client company data, numerous contracts, and scripts developed for the company’s clients to integrate the service on their systems, potentially opening up their systems to threat actor activity. If you are a user of Nextcloud, reach out to your engineers and procurement teams - make sure they verify any communications from Nextcloud for the coming months, just in case that information allows for credible, personalised phishing attacks. cybernews.com/security/nextcloud-cloud-provider-data-leak
