Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
[flagged]
rssathe on May 9, 2023 | hide | past | favorite


Hey Hackernews,

Over the last four years, we have seen rapid growth in sensitive data stored on the cloud, particularly for support agents using Zendesk. This is highlighted by Zendesk’s own CX Trends 2022 Report found that ticket volume had increased across all channels, with webform/email up 10% YoY and chat up 17% YoY.

These findings are supported by a recent study my team at Nightfall completed across thousands of organizations that found on average 10+ API keys unprotected in Zendesk. This makes Zendesk an attractive target for hackers looking for PII, PHI, Passwords and API Keys, and payment information.

I’ve written up a post detailing how to clean up Zendesk to prevent the likelihood of a threat actor getting away with anything sensitive.

Please let me know if you have any questions or feedback.

Cheers, Rohan




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: