Travelex ignored September warning over 'insecure' VPN server software
Currency exchange specialist Travelex was warned about insecure virtual private networking (VPN) servers that it was running in September last year - but that warning appears to have been ignored.
The warning was issued by Chicago, Illinois-based security researcher Troy Mursch, tweeting under his @bad_packets account. He claims that he notified in the organisation about the vulnerable Pulse Secure VPN servers it was running on 13 September, but received no response from the company.
Travelex was one of a number of companies that Mursch informed, also informing the UK's National Cyber Security Centre at the same time. The NCSC sent out warning letters to affected organisations as a result of that warning.
But even now, according to UK-based security specialist Kevin Beaumont, a large number of organisations are still running iterations of Pulse Secure bearing a vulnerability identified 11 months ago.
And one-quarter of those vulnerable servers are located in the US, added Beaumont, at a time when Iran has threatened retaliation for the assassination of a senior general.
Today, the Travelex website and mobile app remain down with what the holding page describes as "planned maintenance". The website and associated currency exchange facilities were taken down on New Year's Eve following what the organisation had claimed was a virus outbreak.
Travelex's action has also affected currency exchange services from Barclays, HSBC, Sainsbury's Bank, First Direct and Virgin Money, which rely on Travelex. Users of the company's pre-paid foreign currency cards have also been affected and left unable to top them up for more than a week.
The vacuum left behind by the lack of information about the nature of the attack has been filled with speculation, with anything from North Korean state actors to ransomware blamed for the extended downtime.
source computing
Industry: Cyber Security News
Latest Jobs
-
- PCI QSA needed. Discreet Opportunity | London | Client facing
- London
- N/A
-
CH08421 PCI QSA needed. Discreet Opportunity | London | Client facing. Payment Card Industry - Qualified Security Assessor - London Seeking someone looking to accelerate their career, into a variety of interesting clients / projects. Must be happy to be onsite with clients- this is not a fully remote role. You must currently hold a valid CISSP or CISM or ISO27001 lead implementer certification AND one of the following; CISA, GSNA, iso27001 lead Auditor, CIA or IRCA ISMS auditor+ Visa sponsorship not available. Apply today for more information chris.holt@dclsearch.com Use this whatapp link to reach out https://wa.me/message/6USF5RAQBOZIP1
-
- Network / Security Infrastructure Engineer | West London | Permanent
- London
- N/A
-
Network / Security Infrastructure Engineer | West London | Current Config, Install, upgrade experience On prem / Datacetner experience essential. Hands on experience MUST include: Routing, Switching, Network Security (firewall, IDS etc), Microsoft exchange / Exchange 365. Scripting / automation experience wanted. Python, Powershell etc Regular travel to West London is required. Visa sponsorship not available. Apply today for more information chris.holt@dclsearch.com Use this whatapp link to reach out https://wa.me/message/6USF5RAQBOZIP1
-
- Security Operations / information Security Analyst / Engineer. London
- London
- N/A
-
Security Operations / information Security Analyst / Engineer needed for a London opportunity. A technical hands on role to investigate, escalate and proactively work to protect a globally recognised brand. Someone with SOC Analyst / security engineering background would be well suited. This position will join a small team and would suit someone that has broad experience across the security threat landscape. Experience / knowledge across industry GRC standards such NIST, ISO27001 etc very advantageous and a priority. You will work across multiple teams proactively working to secure the business. Must be able to commute to Central London 3 days a week. Visa sponsorship not available Apply today to find out more.
-
- Security Cleared Penetration Tester: United Kindom
- N/A
- N/A
-
Security Cleared Penetration Tester Deliver technical Penetration tests to the NCSC CHECK standard. Active CHECK Member or Leader status desirable either in Web Application or Infrastructure. Reach out to find out more. Whatsapp directly here https://wa.me/message/6USF5RAQBOZIP1 Or apply today