{"id":1906,"date":"2024-09-20T08:27:19","date_gmt":"2024-09-20T07:27:19","guid":{"rendered":"https:\/\/aegislens.com\/home\/?p=1906"},"modified":"2024-09-20T08:27:19","modified_gmt":"2024-09-20T07:27:19","slug":"unsecured-default-logins-how-hackers-infiltrate-construction-companies-through-foundation-software-vulnerabilities","status":"publish","type":"post","link":"https:\/\/aegislens.com\/home\/unsecured-default-logins-how-hackers-infiltrate-construction-companies-through-foundation-software-vulnerabilities\/","title":{"rendered":"Unsecured Default Logins: How Hackers Infiltrate Construction Companies through FOUNDATION Software Vulnerabilities"},"content":{"rendered":"<p>ventilation, and air conditioning), and general construction firms.<\/p>\n<h1>Hackers Exploit Default Credentials in FOUNDATION Software to Breach Construction Firms<\/h1>\n<p>Last week, cybersecurity research company Huntress reported a marked increase in attempts to infiltrate FOUNDATION accounting software.<\/p>\n<p>The cybercriminals&#8217; modus operandi is unsophisticated yet highly effective: using the software&#8217;s default credentials to gain unauthorized access to the systems.<\/p>\n<p>The threat actors appear to be targeting companies working within the construction industry, with specific interest in plumbing, HVAC, and general construction companies.<\/p>\n<h2>The Importance of Changing Default Credentials<\/h2>\n<p>FOUNDATION, a popular accounting software widely used within the construction industry to control job expenses and manage project costs, comes with default credentials for ease of setup.<\/p>\n<p>Leaving these default credentials unchanged, however, leaves the door wide open for cybercriminals.<\/p>\n<p>As the researchers at <a href=\"https:\/\/www.huntress.com\/\">Huntress<\/a> point out, threat actors can easily find lists of default credentials on the Internet or in the software&#8217;s user manuals.<\/p>\n<p>Armed with this information, attackers can then proceed to use brute force mechanisms to gain unauthorized access.<\/p>\n<h2>Real-world Examples and Impact<\/h2>\n<p>The damaging potential of such attacks is enormous.<\/p>\n<p>For example, in 2017, a major breach of hospitality software firm Avanti Markets resulted in the compromise of personal data, including biometric information, of millions of customers.<\/p>\n<p>The data breach occurred when hackers exploited the software&#8217;s Default User credentials, highlighting the peril of unchanged default access information.<\/p>\n<h2>Fight Back: Practical Advice on Safeguarding Your Systems<\/h2>\n<p>Companies using FOUNDATION, or indeed any other software, are urged to take the following crucial steps to ensure the security of their data and systems:<\/p>\n<ul>\n<li>Change default credentials: This is the first and most crucial step, yet one which is often overlooked.<\/li>\n<li>Develop a strong password policy: Ensure passwords are complex, not easily guessed, and are changed regularly.<\/li>\n<li>Implement multi-factor authentication: This adds an additional layer of security, making a breach much less likely.<\/li>\n<li>Educate all staff: Ensuring everyone knows the dangers of cyber attacks and the importance of maintaining strong, unique passwords can help to prevent breaches.<\/li>\n<\/ul>\n<p>Cyber threats are now an ever-present reality for businesses across all sectors.<\/p>\n<p>There has never been a more crucial time to ensure that you are doing everything in your power to secure your systems, including simple steps like changing the default credentials on your software.<\/p>\n<h2>Follow-Up Reading<\/h2>\n<ul>\n<li><a href=\"https:\/\/krebsonsecurity.com\/2017\/07\/avanti-micromarket-breached-via-poisonous-picnic\/\">Avanti Markets Data Breach Report &#8211; Krebs on Security<\/a><\/li>\n<li><a href=\"https:\/\/www.zdnet.com\/article\/this-password-stealing-malware-uses-a-new-trick-to-spy-on-you\/\">The Importance of Changing Default Passwords &#8211; ZDNet<\/a><\/li>\n<li><a href=\"https:\/\/www.sans.org\/reading-room\/whitepapers\/bestprac\/problems-stale-passwords-sensitive-accounts-670\">The Problems with Stale Passwords on Sensitive Accounts &#8211; SANS Institute<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>ventilation, and air conditioning), and general construction firms. Hackers Exploit Default Credentials in FOUNDATION Software<\/p>\n","protected":false},"author":1,"featured_media":1907,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pmpro_default_level":"","_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[2,5],"tags":[],"class_list":["post-1906","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-news","pmpro-has-access"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/1906","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/comments?post=1906"}],"version-history":[{"count":1,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/1906\/revisions"}],"predecessor-version":[{"id":1913,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/posts\/1906\/revisions\/1913"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/media\/1907"}],"wp:attachment":[{"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/media?parent=1906"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/categories?post=1906"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aegislens.com\/home\/wp-json\/wp\/v2\/tags?post=1906"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}