#uberunderpaiddrivers
Many Uber employees initially thought it was a joke, the Washington Post reports.
Lessons learned:
No hardcoded credentials and temperate keys, such as SSH, VPN, cloud credentials, etc. Scan your shares and assets for hardcoded credentials before hackers do that. That’s an easy task.
Always require 2FA/MFA for VPN. Split intranet by zones even inside VPN; segmentation required.
Use API security solutions, such as Wallarm, to protect internal services and systems, such as PAM, corporate portals, and management systems. It also helps with leaked API token blocking and investigations.