Company
Date Published
Author
Andreas Nilsson
Word count
806
Language
English
Hacker News points
12

Summary

The text discusses malicious attacks on unsecured MongoDB instances, which have resulted in attackers erasing databases and demanding ransom payments. These attacks are preventable with the extensive security protections built into MongoDB, including authentication, access control, network exposure limits, and continuous backups. To avoid such attacks, users should follow best practices outlined in the Security Checklist and utilize features like MongoDB Cloud Manager and Ops Manager for monitoring and backup purposes. Additionally, the latest MongoDB release enables authentication to an unprotected system without downtime, while the Atlas hosted database service provides robust security measures out of the box. Users who have experienced a security incident with MongoDB are encouraged to report vulnerabilities and seek guidance from the company's security documentation and resources.