<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: URLscan.io's SOAR spot: Chatty security tools leaking private data! in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/urlscan-io-s-soar-spot-chatty-security-tools-leaking-private/m-p/528465#M1710</link>
    <description>&lt;P&gt;Good point, I was thinking the private option would work only with premium licenses of URL Scan , if thats the case and no premium licenses, best to watch what is the integration used for and reduce its usage.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jan 2023 03:29:26 GMT</pubDate>
    <dc:creator>sramesh-7</dc:creator>
    <dc:date>2023-01-25T03:29:26Z</dc:date>
    <item>
      <title>URLscan.io's SOAR spot: Chatty security tools leaking private data!</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/urlscan-io-s-soar-spot-chatty-security-tools-leaking-private/m-p/528235#M1689</link>
      <description>&lt;P&gt;Community, have you noticed that we may be accidentally exposing confidential information of the users we protect by submitting URLs for analysis to URLscan.io?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Credits to: FABIAN BRAUNLEIN" style="width: 520px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47347iA98A680CCB626FDC/image-dimensions/520x301/is-moderation-mode/true?v=v2" width="520" height="301" role="button" title="urlscan.PNG" alt="Credits to: FABIAN BRAUNLEIN" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Credits to: FABIAN BRAUNLEIN&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Sensitive URLs to shared documents, password reset pages, team invites, payment invoices and more are publicly listed and searchable on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="http://urlscan.io/" target="_blank" rel="noopener"&gt;urlscan.io&lt;/A&gt;, a security tool used to analyze URLs&lt;/LI&gt;
&lt;LI&gt;Part of the data has been leaked in an automated way by other security tools that accidentally made their scans public (as did GitHub earlier this year)&lt;/LI&gt;
&lt;LI&gt;If we don't take the proper measures regarding the configuration of URL scanning through the XSOAR integration and URLscan.io we have a high risk of your accounts being hijacked through manually activated password resets.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am attaching an image with a simple mitigation measure in the configuration (Instance Settings), in case you have not applied it yet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="XSOAR CONFIG - Prevent.png" style="width: 670px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47348i2DD22F0165FDDDA8/image-dimensions/670x417/is-moderation-mode/true?v=v2" width="670" height="417" role="button" title="XSOAR CONFIG - Prevent.png" alt="XSOAR CONFIG - Prevent.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 21:33:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/urlscan-io-s-soar-spot-chatty-security-tools-leaking-private/m-p/528235#M1689</guid>
      <dc:creator>LuisElolaPrev</dc:creator>
      <dc:date>2023-01-23T21:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: URLscan.io's SOAR spot: Chatty security tools leaking private data!</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/urlscan-io-s-soar-spot-chatty-security-tools-leaking-private/m-p/528465#M1710</link>
      <description>&lt;P&gt;Good point, I was thinking the private option would work only with premium licenses of URL Scan , if thats the case and no premium licenses, best to watch what is the integration used for and reduce its usage.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 03:29:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/urlscan-io-s-soar-spot-chatty-security-tools-leaking-private/m-p/528465#M1710</guid>
      <dc:creator>sramesh-7</dc:creator>
      <dc:date>2023-01-25T03:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: URLscan.io's SOAR spot: Chatty security tools leaking private data!</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/urlscan-io-s-soar-spot-chatty-security-tools-leaking-private/m-p/528546#M1718</link>
      <description>&lt;P&gt;Exactly!&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 13:59:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/urlscan-io-s-soar-spot-chatty-security-tools-leaking-private/m-p/528546#M1718</guid>
      <dc:creator>LuisElolaPrev</dc:creator>
      <dc:date>2023-01-25T13:59:35Z</dc:date>
    </item>
  </channel>
</rss>

