Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
EY’s 4TB SQL Server Backup File On Microsoft Azure Exposed Publically

EY’s 4TB SQL Server Backup File On Microsoft Azure Exposed Publically

Posted on October 29, 2025October 29, 2025 By CWS

A large 4TB SQL Server backup file belonging to world accounting big Ernst & Younger (EY) was found publicly accessible on Microsoft Azure.

The publicity, uncovered by cybersecurity agency Neo Safety throughout a routine asset mapping train, highlights how even well-resourced organizations can inadvertently go away delicate knowledge susceptible to the web’s automated scanners.

Neo Safety’s lead researcher found the file whereas analyzing passive community site visitors with low-level instruments.

A easy HEAD request meant to fetch metadata with out downloading content material revealed the staggering dimension: 4 terabytes of knowledge, equal to tens of millions of paperwork or a complete library’s value of knowledge.

The file’s naming conference screamed SQL Server backup (.BAK format), which generally accommodates full database dumps, together with schemas, person knowledge, and, crucially, embedded secrets and techniques reminiscent of API keys, credentials, and authentication tokens.

Discovery and Verification Course of

Preliminary searches on the Azure Blob Storage yielded no speedy possession clues, however deeper probes uncovered merger paperwork in a European language, translated with instruments like DeepL, pointing to a 2020 acquisition.

A pivotal DNS SOA file lookup tied the area to ey.com, confirming EY’s involvement. To keep away from any authorized pitfalls, the workforce downloaded solely the file’s first 1,000 bytes, revealing an unmistakable “magic bytes” signature for an unencrypted SQL Server backup, Neo Safety learns.

This was not a theoretical threat. Neo Safety relied on real-world incident response expertise, recalling a fintech breach that resulted from the temporary publicity of the same .BAK file for simply 5 minutes.

In that case, attackers exploited the temporary window to exfiltrate personally identifiable info and credentials, resulting in ransomware and the corporate’s collapse.

With at present’s botnets scanning your entire IPv4 tackle area in minutes, such exposures invite inevitable compromise. Neo Safety halted additional probing and pursued accountable disclosure over a weekend, finally connecting with EY’s CSIRT by way of LinkedIn outreach after 15 makes an attempt.

EY responded swiftly and professionally, triaging and remediating the difficulty inside every week, with no defensiveness, simply efficient motion.

The agency deserves credit score for its mature dealing with, a rarity in an trade usually marred by denial or delays. But the incident underscores systemic cloud vulnerabilities. Azure’s comfort in exporting databases can result in ACL (Entry Management Checklist) errors, flipping personal storage public with one misclick.

For EY a Massive 4 agency auditing billion-dollar offers and holding market-moving monetary knowledge this lapse raises questions on oversight in fast-paced infrastructures.

Consultants warn that automated adversarial scanning means exposures aren’t “if” however “what number of” actors discover.

As cloud complexity grows, steady mapping and visibility instruments grow to be important to outpace threats, making certain organizations uncover their very own leaks first.

Comply with us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:4TB, Azure, Backup, Exposed, EYs, File, Microsoft, Publically, Server, SQL

Post navigation

Previous Post: Microsoft DNS Outage Disrupts Azure and Microsoft 365 Services Worldwide
Next Post: Huge Surge in Fake Investment Platforms Mimic Forex Exchanges Steal Logins

Related Posts

Zero Trust Guidelines for Protecting Industrial Systems Zero Trust Guidelines for Protecting Industrial Systems Cyber Security News
Hands-on Cybersecurity Threat Hunting Guide for SOC Analysts and MSSPs Hands-on Cybersecurity Threat Hunting Guide for SOC Analysts and MSSPs Cyber Security News
WhatsApp Developers Under Attack From Weaponized npm Packages with Remote Kill Switch WhatsApp Developers Under Attack From Weaponized npm Packages with Remote Kill Switch Cyber Security News
Surveillance Company Using SS7 Bypass Attack to Track the User’s Location Information Surveillance Company Using SS7 Bypass Attack to Track the User’s Location Information Cyber Security News
Silver Fox APT Hackers Leveraging Vulnerable Driver to Attack Windows 10 and 11 Systems by Evading EDR/AV Silver Fox APT Hackers Leveraging Vulnerable Driver to Attack Windows 10 and 11 Systems by Evading EDR/AV Cyber Security News
“GPUGate” Malware Abuses Uses Google Ads and GitHub to Deliver Advanced Malware Payload “GPUGate” Malware Abuses Uses Google Ads and GitHub to Deliver Advanced Malware Payload Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution
  • Critical 18-Year NGINX Vulnerability Enables Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution
  • Critical 18-Year NGINX Vulnerability Enables Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark