Query failed: connection to localhost:9312 failed (errno=111, msg=Connection refused). Quad Cortex security vulnerability - possible data breach - Digital & Modelling Discussions on The Fretboard
UNPLANNED DOWNTIME: 12th Oct 23:45

Quad Cortex security vulnerability - possible data breach

What's Hot
Just received this email:

On Friday April 21st we were alerted to an unsuccessful login to the email account we use to collect reports and logs sent from Quad Cortex. This turned our attention to a security vulnerability on Quad Cortex that granted exploiters temporary access to the aforementioned email account.

This exploit was immediately fixed internally, meaning no further access is possible. However, this has resulted in Quad Cortex being unable to send new reports or logs until CorOS 2.0.2 has been installed.

We are beta testing CorOS 2.0.2 internally and intend to release it this week. 

Unfortunately, due to the exploit, approximately 3300 names and email addresses were viewable by a small number of individuals who are attempting to expose security vulnerabilities on Quad Cortex. This does not mean the exploiters were able to log in to the email accounts - they could only see the names and email addresses in a list.

While the exploiters were able to access the inbox of the email account containing the reports and logs, they did not, to the best of our knowledge, exploit this breach with malicious intent to gain access to customer data.

Quad Cortex also records the names and passwords of all the WiFi networks it has connected to since the last factory reset. Unfortunately this data was not encrypted.

The WiFi passwords for any user who sent a crash log to us (after a system failure, not by sending a log via Settings > Contact Us > Send Report) were also accessible to the exploiters.

We identified approximately 430 users affected by this. This issue has been fixed in CorOS 2.0.2, and Quad Cortex will no longer record the passwords of WiFi networks in the crash logs.

No further personal information or sensitive data is collected by Quad Cortex and, therefore, nothing else has been exposed.

We have emailed the users who have been affected by this breach. If you have ever sent a Quad Cortex report or a crash log, the above applies to you. If you have not sent a Quad Cortex report or a crash log, your name, email address, or WiFi password has not been exposed.

I apologize deeply for this inconvenience and our oversight. We value our users’ privacy above anything else and we were devastated to learn of this vulnerability being exploited. We will be doing everything possible to deeply evaluate our systems and Quad Cortex to ensure nothing like this can happen again.

If you have any questions, please do not hesitate to contact support@neuraldsp.com

This week's procrastination forum might be moved to sometime next week.
0reaction image LOL 2reaction image Wow! 0reaction image Wisdom · Share on Twitter

Comments

  • nero1701nero1701 Frets: 770
    edited April 2023
    I got it also. Pain in the cock..

    Means changing the password on router...then some 18 devices.. 

    Maybe I should send a fucking bill for the hourly rate of my fkin time to them!
    My Trading Feedback

    "If it smells like shit...It is probably shit"
    1reaction image LOL 0reaction image Wow! 4reaction image Wisdom · Share on Twitter
  • maharg101maharg101 Frets: 568
    What the fuck sort of system is that ? Sending error reports by email, including sensitive values (which it has no business sending at all) in the clear. Epic, epic fail.
    This one goes to eleven

    Trading feedback here
    0reaction image LOL 0reaction image Wow! 5reaction image Wisdom · Share on Twitter
  • Bats_Bats_ Frets: 29
    Daaaaaaaamn!!!

    that’s some serious data collection that’s totally unnecessary. 

     We have emailed the users who have been affected by this breach. If you have ever sent a Quad Cortex report or a crash log, the above applies to you. If you have not sent a Quad Cortex report or a crash log, your name, email address, or WiFi password has not been exposed”
    0reaction image LOL 0reaction image Wow! 1reaction image Wisdom · Share on Twitter
  • Secret_SamSecret_Sam Frets: 202
    edited April 2023
    More importantly, the Chinese government now knows what amp models you prefer. And the Russians are checking to see if you choose the approved Soviet version of the Big Muff. 
    7reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • BillDLBillDL Frets: 5615
    Those affected can now look forward to endless spam and scam emails after the database of 33,000 names and email addresses is sold on to many others or published openly for download by the "small number of individuals who are attempting to expose security vulnerabilities".
    0reaction image LOL 0reaction image Wow! 4reaction image Wisdom · Share on Twitter
  • kjdowdkjdowd Frets: 851
    edited April 2023
    Bats_ said:
    Daaaaaaaamn!!!

    that’s some serious data collection that’s totally unnecessary. 

    “ We have emailed the users who have been affected by this breach. If you have ever sent a Quad Cortex report or a crash log, the above applies to you. If you have not sent a Quad Cortex report or a crash log, your name, email address, or WiFi password has not been exposed”
    Yes. Lots of questions to ask there, chief among them what the hell is the user's wifi password (or any other password for that matter) doing appearing in a crash log!
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • robertyroberty Frets: 10231
    kjdowd said:
    Bats_ said:
    Daaaaaaaamn!!!

    that’s some serious data collection that’s totally unnecessary. 

    “ We have emailed the users who have been affected by this breach. If you have ever sent a Quad Cortex report or a crash log, the above applies to you. If you have not sent a Quad Cortex report or a crash log, your name, email address, or WiFi password has not been exposed”
    Yes. Lots of questions to ask there, chief among them what the hell is the user's wifi password (or any other password for that matter) doing appearing in a crash log!
    Yikes
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • normula1normula1 Frets: 618
    Sounds like a GDPR claim in the making.
    0reaction image LOL 0reaction image Wow! 4reaction image Wisdom · Share on Twitter
  • OnTheHuntOnTheHunt Frets: 56
    Another score for my stinky old 50s/60s tech valve powered jobbies. 

    Seriously though, that’s not a good breach. Passwords, clear text…… oooff! Wonder what else the average QC user doesn’t know it’s doing under the hood…..
    1reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • marxskimarxski Frets: 201
    “We”ll just stick em in a CSV file for now…”
    1reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • AntonHunterAntonHunter Frets: 837
    OnTheHunt said:
    Another score for my stinky old 50s/60s tech valve powered jobbies. 


    My stompboxes are yet to email anyone, let alone include my WiFi password in that email!
    0reaction image LOL 0reaction image Wow! 0reaction image Wisdom · Share on Twitter
  • danodano Frets: 1484
    Its time like this I'm glad of my Fuzz Face, Rat and DD3 
    0reaction image LOL 0reaction image Wow! 1reaction image Wisdom · Share on Twitter
Sign In or Register to comment.