{"id":5078,"date":"2024-08-29T14:34:28","date_gmt":"2024-08-29T19:34:28","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/top-travel-sites-have-some-first-class-security-issues-to-clean-up"},"modified":"2024-08-29T14:34:28","modified_gmt":"2024-08-29T19:34:28","slug":"top-travel-sites-have-some-first-class-security-issues-to-clean-up","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/29\/top-travel-sites-have-some-first-class-security-issues-to-clean-up\/","title":{"rendered":"Top Travel Sites Have Some First-Class Security Issues to Clean Up"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltffad5066a42356fb\/66d05b556a198a84519be2b2\/vacation-anastasia-nelen-unsplash.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/top-travel-sites-have-some-first-class-security-issues-to-clean-up.png?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/top-travel-sites-have-some-first-class-security-issues-to-clean-up.png?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The top 10 travel and hospitality companies have public-facing security and other <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/7-critical-cloud-threats-facing-enterprise-2023\" rel=\"noopener\">cloud infrastructure vulnerabilities<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that expose customers to potential security risks, research has found.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Security vendor Cequence investigated the top 10 sites that people use to book flights, hotels, car rentals, and holiday packages online \u2014 including Orbitz, Kayak, Skyscanner, and Travelocity \u2014 and found that all of them have serious security flaws that can put site visitors at risk for compromise as well as negatively affect their own businesses and reputations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The researchers didn&#8217;t name the most perilous companies for travelers to use, but did note that their online systems contained 91% of the most serious vulnerabilities that were discovered. Moreover, most of these flaws allow for man-in-the-middle (MiTM) attacks in which attackers can intercept and manipulate communciations with users.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Other security holes that Cequence researchers discovered are related to the actual infrastructure of the service provider&#8217;s website, with common issues related to cloud infrastructure creating insecure scenarios for public users.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Indeed, no matter where the risk stems from, what it boils down to is that people booking holiday or business travel online could unwittingly be compromised in a number of ways, particularly during peak travel times when attackers know travel sites will be busy, noted William Glazier, director of threat research at Cequence. This, in turn, demands that providers and consumers alike be mindful and make appropriate modifications to infrastructure and online behavior, respectively, to keep attackers at bay, he said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Our research highlights severe threats, including financial loss, identity theft, and disrupted travel for consumers, and reputational damage and legal issues for businesses,&#8221; Glazier said, in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cequence.ai\/news\/travel-websites-at-risk-100-of-top-sites-exposed-to-severe-cyber-threats-as-labor-day-approaches\/\" rel=\"noopener\">a press statement<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Existing Security Holes\">Existing Security Holes<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The flaws that Cequence found in travel organizations&#8217; back-end infrastructure were less straightforward than software or hardware <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/remote-workforce\/critical-aws-vulnerabilities-allow-s3-attack-bonanza\" rel=\"noopener\">vulnerabilities<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, though those existed as well. They found <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/new-startup-opshelm-tackles-cloud-misconfigurations\" rel=\"noopener\">misconfigurations<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and other problems plaguing the cloud infrastructure that supports many travel and hospitality websites.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Eight out of the 10 companies had public-facing, non-production or internal application servers in their environments \u2014 systems that are typically unmonitored and unmanaged by IT staff. These assets, as many as 300 at one of the companies \u2014 allow threat actors system access, according to Cequence.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">All of the service providers also showed signs of cloud sprawl, where systems got deployed faster than they could be effectively managed. Cequence found that the top travel and hospitality sites used between five and 21 different hosting providers; Amazon Web Services is the most widely used cloud infrastructure provider, followed by Google and Microsoft.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This sprawl leads to a proliferation of public-facing cloud instances and underscores the complexity of managing cloud environments, according to Cequence. It also creates a situation in which organizations don&#8217;t even know what technology assets exist in their network, let alone make sure they&#8217;re secured. Further, this scenario can ensnarl companies in supply-chain attacks that don&#8217;t originate in their own infrastructure but float downstream from another provider.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Outlook Demands Better Security\">Outlook Demands Better Security<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">While Cequence did not disclose the names of the worst security offenders of the companies analyzed, it did share which sites were among the safest. Those who locked down internal application or non-production servers and had the least amount accessible to public-facing apps were, in this order: Orbitz and Travelocity, Kayak, and Skyscanner.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Meanwhile, these companies also had the fewest number of vulnerabilities in their public-facing applications that might affect clients visiting their sites. In this instance, Skyscanner performed the best, followed by Kayak and Orbitz.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As summer wanes, there are two significant milestones in the near future that demand an examination of security by travel and hospitality companies to ensure their online booking systems are safer for consumers.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One is the arrival of PCI DSS v4.0, a security standard that governs handling of credit card information that goes into effect in April 2025, and has several new requirements for online credit-card safety. Companies must ensure compliance by that time or face fines, penalties, and disruptions <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/santander-falls-victim-to-data-breach-involving-third-party-provider\" rel=\"noopener\">to card transactions<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, along with increased risk of data breaches that could damage their reputations and create trust issues with customers, according to Cequence.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The other is the busy winter-travel season, which typically kicks off in October and invites attackers to launch a flurry of distributed denial-of-service (DDoS) attacks. Indeed, in November 2023 travel sites racked up almost double the number of DDoS attacks over the next-highest month, Cequence noted.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/top-travel-sites-have-some-first-class-security-issues-to-clean-up\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The top 10 travel and hospitality companies have public-facing security<\/p>\n","protected":false},"author":12,"featured_media":5079,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5078","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/top-travel-sites-have-some-first-class-security-issues-to-clean-up.png?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/top-travel-sites-have-some-first-class-security-issues-to-clean-up.png?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/top-travel-sites-have-some-first-class-security-issues-to-clean-up.png?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/top-travel-sites-have-some-first-class-security-issues-to-clean-up.png?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/top-travel-sites-have-some-first-class-security-issues-to-clean-up.png?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/top-travel-sites-have-some-first-class-security-issues-to-clean-up.png?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/top-travel-sites-have-some-first-class-security-issues-to-clean-up.png?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/top-travel-sites-have-some-first-class-security-issues-to-clean-up.png?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/top-travel-sites-have-some-first-class-security-issues-to-clean-up.png?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/top-travel-sites-have-some-first-class-security-issues-to-clean-up.png?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/top-travel-sites-have-some-first-class-security-issues-to-clean-up.png?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5078","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5078"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5078\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5079"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5078"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5078"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5078"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}