Legacy sign-on service comes back to bite school software provider Bromcom
Intruders retrieved email addresses from a superseded sign-on service that school software provider Bromcom kept running for an internal system, The Register reports. The incident is a textbook case of legacy infrastructure expanding the attack surface long after it should have been retired.