News Article · Jul 16, 2026 at 11:47 AM
2 min read 0
Member
Law Firm Master Password, Qantas Breach Highlight Persistent Security Gaps
Security #social engineering #zero-day #data breach #password security #patch management #Qantas #cyber insurance

Law Firm Master Password, Qantas Breach Highlight Persistent Security Gaps

A law firm's single admin password allowed impersonation of any user, while a tech support scam exposed 5.7 million Qantas customers. Meanwhile, a Windows zero-day and vendor patches underscore the patchwork of threats.

Two incidents this week illustrate how basic security failures continue to plague organizations. A law firm relied on a single master password that let anyone impersonate any user, and a tech support scam at Australian airline Qantas exposed personal data of 5.7 million people. The breaches come as the cyber insurance protection gap is estimated at $900 billion, according to the Global Federation of Insurance Associations.

The law firm, described by a former IT employee to The Register, used a 15-year-old web-based system where a single admin password granted access to any client or staff account. The employee who discovered the flaw was told not to touch it. The system allowed anyone with the password to view health records, reassign work, or complete client forms without authorization.

Shared Credentials and Social Engineering

The Qantas breach, also reported by The Register, originated from a tech support scam that tricked an employee into granting remote access. The attacker then exfiltrated data on 5.7 million customers, including names, addresses, and travel details. Qantas stated the incident did not breach privacy regulations, a claim that has drawn skepticism from security experts.

  • Law firm system: 15 years old, single admin password shared across all users, no audit trail for impersonation.
  • Qantas breach: 5.7 million records exposed via a social engineering attack on a help desk employee.
  • Both incidents involved weak access controls and insufficient employee training.

Zero-Day Exploits and Vendor Patches

Separately, researcher Nightmare Eclipse released details of a Windows zero-day dubbed LegacyHive, but stripped the proof-of-concept exploit to prevent immediate abuse. The vulnerability affects legacy components in Windows and could allow privilege escalation. SecurityWeek reported that the researcher withheld the full exploit code to give Microsoft time to patch.

Meanwhile, Trend Micro, Tanium, ESET, and Tenable all issued patches for critical and high-severity vulnerabilities in their products. The patches address remote code execution and privilege escalation flaws that could be chained with other exploits. Organizations are urged to apply updates promptly.

The combination of weak internal controls, social engineering, and unpatched software creates a challenging risk landscape. Insurers are responding by tightening policy terms and requiring evidence of multi-factor authentication and regular patching. The $900 billion protection gap suggests many organizations remain underinsured or uninsured against the true cost of a breach.

Fact check

  • A law firm used a single master password that allowed impersonation of any user.

    reported · source

  • A tech support scam at Qantas exposed personal data of 5.7 million people.

    reported · source

  • The cyber insurance protection gap is estimated at $900 billion by the Global Federation of Insurance Associations.

    reported · source

  • Researcher Nightmare Eclipse released details of a Windows zero-day called LegacyHive but stripped the proof-of-concept exploit.

    reported · source

  • Trend Micro, Tanium, ESET, and Tenable patched critical and high-severity vulnerabilities in their products.

    reported · source

Source reporting (12)

0 Comments

No comments yet

Be the first to share your thoughts on this article.

Join the conversation

You need to be registered and logged in to comment on blog articles.

Who Is Online

In total there are 45 users online: 0 registered, 37 guests and 8 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Majestic Other Bot PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 370