This strange email vulnerability is exposing corporate secrets to anyone who acquires the correct domain.

This strange email vulnerability is exposing corporate secrets to anyone who acquires the correct domain.

      Security researchers have found that companies are unintentionally sending sensitive emails to domains that can be registered by outsiders.

      You don't always need to breach a company's systems to access its secrets. Sometimes, companies will just send them to you via email. A recent report by Matt Burgess from WIRED has revealed an unusual email security issue where companies mistakenly send sensitive information to domains that can be controlled by third parties. Security researchers Cory Solovevich and Mike Sheward found that seemingly harmless addresses like noreply and deleteduser can unintentionally become gateways to corporate data if the domains are not properly managed.

      The “hack” involves acquiring the right domain.

      What is concerning is that this doesn't require advanced hacking skills. Solovevich found that domains like noreply.net and noreply.us were receiving large volumes of emails that companies likely assumed would be untraceable.

      Instead, these messages were landing in an inbox he controlled. According to WIRED, noreply.net received over 400,000 messages within a year and a half, including more than 28,000 attachments. The emails varied from routine notifications to employee details and other confidential business information.

      Sheward faced a similar situation after acquiring deleteduser.com, where he received thousands of unintended emails with content such as vacation requests, hotel reservations, employee names, and Zoom invitations. The core issue is relatively straightforward. Companies sometimes use temporary email addresses for accounts that no longer exist, thinking that no one can access those addresses. However, if the domain linked to that address is no longer controlled by the organization and is registered by someone else, those emails that were meant to be lost can suddenly reach a very real recipient.

      This situation is more than just a few misplaced emails.

      The researchers discovered that the issue could be extensive. Solovevich identified 7,136 domains set up to receive emails, including 328 with catch-all inboxes able to accept messages sent to different addresses within those domains. While not all these domains are necessarily leaking sensitive information, it underscores how easily overlooked email configurations can pose a security risk.

      Fortunately, Solovevich and Sheward are informing affected organizations instead of exploiting the information they obtain. Solovevich has also purchased over 30 domains to stop malicious actors from taking advantage of this vulnerability.

      The broader takeaway from WIRED's investigation is quite straightforward: an email address is not a void just because a company believes it to be. Organizations may invest millions in safeguarding their networks against sophisticated attacks, but if sensitive emails are still directed to domains that can be bought by others, sometimes the simplest way to access a company's secrets is by owning the right piece of digital property.

This strange email vulnerability is exposing corporate secrets to anyone who acquires the correct domain. This strange email vulnerability is exposing corporate secrets to anyone who acquires the correct domain. This strange email vulnerability is exposing corporate secrets to anyone who acquires the correct domain. This strange email vulnerability is exposing corporate secrets to anyone who acquires the correct domain. This strange email vulnerability is exposing corporate secrets to anyone who acquires the correct domain. This strange email vulnerability is exposing corporate secrets to anyone who acquires the correct domain. This strange email vulnerability is exposing corporate secrets to anyone who acquires the correct domain.

Other articles

I discovered three ChatGPT features that ended up being far more helpful than I anticipated. I discovered three ChatGPT features that ended up being far more helpful than I anticipated. I discovered three ChatGPT features that greatly simplified my daily workflow, and I believe you'll want to give them a try as well. According to a report, Apple is considering developing a wearable device without a screen to compete with Whoop and Fitbit Air. According to a report, Apple is considering developing a wearable device without a screen to compete with Whoop and Fitbit Air. Bloomberg's report indicates that Apple is contemplating a revamp of its wearable devices, which includes plans to create a fitness tracker that can be worn on the wrist without a screen. Apple may be considering a circular display as it prepares for a refresh of its smartwatch. Apple may be considering a circular display as it prepares for a refresh of its smartwatch. In 2017, we discovered an Apple patent for a smartwatch featuring a round display. It appears that Apple is now contemplating a redesign. The Apple Watch may become extremely costly with the introduction of new high-end models. The Apple Watch may become extremely costly with the introduction of new high-end models. Apple is said to be exploring the introduction of new high-end Watch models that would be positioned above the Ultra and Hermès collections as part of a comprehensive revamp of its smartwatch offerings. Lofree Flow 2 review: This keyboard made me feel like I typed more quickly, but it also challenged my patience. Lofree Flow 2 review: This keyboard made me feel like I typed more quickly, but it also challenged my patience. The Lofree Flow 2 excels in the most crucial aspect of a keyboard, but some odd choices complicate the overall typing experience more than it should be. The payouts for creators on X are being updated, with original content becoming the new form of currency. The payouts for creators on X are being updated, with original content becoming the new form of currency. X is discontinuing its Revenue Sharing program and introducing Original Content Rewards, reallocating funds to prioritize original posts, videos, photos, and substantial commentary.

This strange email vulnerability is exposing corporate secrets to anyone who acquires the correct domain.

According to a recent report, a strange email security vulnerability is leading companies to transmit sensitive information to domains that can be registered by outsiders.