<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Apache Struts on Locodigital</title><link>https://locodigital.com.br/en/tags/apache-struts/</link><description>Recent content in Apache Struts on Locodigital</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sat, 29 Aug 2026 09:00:00 -0300</lastBuildDate><atom:link href="https://locodigital.com.br/en/tags/apache-struts/index.xml" rel="self" type="application/rss+xml"/><item><title>How Equifax ignored one patch and exposed 147 million people</title><link>https://locodigital.com.br/en/technology/equifax-breach-2017-unpatched-apache-struts/</link><pubDate>Sat, 29 Aug 2026 09:00:00 -0300</pubDate><guid>https://locodigital.com.br/en/technology/equifax-breach-2017-unpatched-apache-struts/</guid><description>&lt;p&gt;On July 29, 2017, an Equifax security analyst noticed suspicious traffic leaving the network. What the investigation revealed over the following hours was alarming: hackers had been inside the company's systems for &lt;strong&gt;76 days&lt;/strong&gt;, quietly sweeping databases holding personal information on half of the adult population of the United States. The way in? A patch that had been available for months and simply was never applied.&lt;/p&gt;
&lt;h2&gt;A known vulnerability, ignored for months&lt;/h2&gt;
&lt;p&gt;On March 7, 2017, the Apache Software Foundation publicly disclosed &lt;strong&gt;CVE-2017-5638&lt;/strong&gt;, a critical flaw in the Apache Struts framework that allows unauthenticated remote code execution. The patch was released the same day. Two days later, on March 9, Equifax's security team sent an internal notice instructing teams to apply the fix urgently.&lt;/p&gt;</description></item></channel></rss>