It’s never pleasant to bring news like this, especially when it involves a security solution, but we can’t stick our heads in the sand and pretend it isn’t there. The point is that the folks at Bitdefender were the victims of a cyberattack, in which partial information about their customers was leaked. The good news is that the vulnerability was fixed, and that neither the “average” consumer nor the enterprise user will be affected. The bad news is that Bitdefender stored passwords in plain text…

If you use Bitdefender antivirus, you should read this…
Bitdefender

It’s supposed to happen to the best. Companies dedicated to providing security solutions are themselves a giant target for malicious elements, and Bitdefender is no exception. The first rumors surfaced during the last week of July, anticipating that the company was under cyber-extortion. A Twitter user by the name of Detox Ransome demanded the sum of $15,000 from Bitdefender, and if the payment was not made, the customer database would be exposed to the web. The alleged attacker published as proof the credentials of two company employees, as well as a client, followed by a small “sample” with data of 250 more clients. The most serious part? The usernames and passwords were extracted in plain text, without any kind of protection on the server.

If you use Bitdefender antivirus, you should read this…
Clients of small and medium businesses were most affected by the attack.

According to the available information, the leaked data belongs to the database that includes small and medium businesses, so regular users and high-profile corporate clients would not be affected. Bitdefender spokespeople said it was “less than one percent” of their clients, and that the vulnerability exploited by the hacker only allowed a partial exposure of credentials, rather than full access to the database. Bitdefender fixed the bug and contacted affected users, indicating that passwords were invalidated to force a change.

The system I’m writing these lines on uses Bitdefender Free as its main antivirus, and I can guarantee you it would have been a unique spectacle to see it fly and narrate the details for your entertainment… but nothing happened here, nor on the other terminal that also uses Bitdefender. Personally, I don’t believe the company’s tools have been compromised, and deep down that’s what matters most, but the idea of storing customer information unencrypted is disturbing. In a security company, even sneezes in an office should be protected…

Source: