#data-exposure

[ follow ]

Data broker leaves 600K+ sensitive files exposed online

Over 600,000 sensitive files, including personal data, were exposed in a non-password protected database belonging to SL Data Services.
#access-control

Misconfigurations in Microsoft Power Pages could expose millions of sensitive records

Misconfigured access controls in Microsoft Power Pages have exposed millions of records, highlighting the need for careful management of security settings.

Configuration flaw puts ServiceNow Knowledge Base articles at risk

Misconfiguration of over 1,000 ServiceNow KB articles risks exposing sensitive data, emphasizing the need for vigilance in SaaS security configurations.

Misconfigurations in Microsoft Power Pages could expose millions of sensitive records

Misconfigured access controls in Microsoft Power Pages have exposed millions of records, highlighting the need for careful management of security settings.

Configuration flaw puts ServiceNow Knowledge Base articles at risk

Misconfiguration of over 1,000 ServiceNow KB articles risks exposing sensitive data, emphasizing the need for vigilance in SaaS security configurations.
moreaccess-control
#cybersecurity

Default app settings can pose a risk to user privacy

Default privacy settings in mobile apps can expose users to privacy risks despite their intended convenience.

Warning to iPhone users about feature that can expose your data

Apple's Mirroring feature contains a major privacy risk that exposes user data, requiring immediate attention from both users and companies.

Indian government's cloud spilled citizens' personal data online for years | TechCrunch

Years-long cybersecurity issue with Indian government's cloud service finally resolved
Sensitive data including Aadhaar numbers and passport details exposed due to misconfiguration

Experts Uncover Severe AWS Flaws Leading to RCE, Data Theft, and Full-Service Takeovers

Multiple critical AWS flaws discovered by cybersecurity researchers, including 'Bucket Monopoly' attack vector leading to severe consequences.

Microsoft ties executive pay to security following multiple failures and breaches

Microsoft faced major security breaches resulting in data exposure and criticism. The company is taking steps to improve its security practices and prioritize security as the top concern.

Obsidian Security Warns of Rising SaaS Threats to Enterprises

SaaS environments pose significant cybersecurity risks in Australia and APAC due to misunderstandings about shared responsibility models.

Default app settings can pose a risk to user privacy

Default privacy settings in mobile apps can expose users to privacy risks despite their intended convenience.

Warning to iPhone users about feature that can expose your data

Apple's Mirroring feature contains a major privacy risk that exposes user data, requiring immediate attention from both users and companies.

Indian government's cloud spilled citizens' personal data online for years | TechCrunch

Years-long cybersecurity issue with Indian government's cloud service finally resolved
Sensitive data including Aadhaar numbers and passport details exposed due to misconfiguration

Experts Uncover Severe AWS Flaws Leading to RCE, Data Theft, and Full-Service Takeovers

Multiple critical AWS flaws discovered by cybersecurity researchers, including 'Bucket Monopoly' attack vector leading to severe consequences.

Microsoft ties executive pay to security following multiple failures and breaches

Microsoft faced major security breaches resulting in data exposure and criticism. The company is taking steps to improve its security practices and prioritize security as the top concern.

Obsidian Security Warns of Rising SaaS Threats to Enterprises

SaaS environments pose significant cybersecurity risks in Australia and APAC due to misunderstandings about shared responsibility models.
morecybersecurity

Misconfigured ServiceNow Knowledge Bases Expose Confidential Information

ServiceNow users may inadvertently expose sensitive information due to misconfigurations in their Knowledge Bases.

Code Smell 263 - Squatting | HackerNoon

Avoid predictable naming patterns to secure cloud resources from unauthorized access and vulnerabilities.
#security-breach

A group of R1 jailbreakers found a massive security flaw in Rabbit's code

API keys hardcoded in Rabbit's codebase put sensitive information at risk of exposure.
Rabbitude gained access to keys, highlighting security weaknesses despite Rabbit's lack of action.
Rabbit's R1 device faced disappointment post-launch, addressing issues like battery life and AI response errors.

South Korea Reports Leak From Its Military Intelligence Command

South Korea's top military intelligence command experienced a leak, risking the exposure of sensitive information to North Korea.

A group of R1 jailbreakers found a massive security flaw in Rabbit's code

API keys hardcoded in Rabbit's codebase put sensitive information at risk of exposure.
Rabbitude gained access to keys, highlighting security weaknesses despite Rabbit's lack of action.
Rabbit's R1 device faced disappointment post-launch, addressing issues like battery life and AI response errors.

South Korea Reports Leak From Its Military Intelligence Command

South Korea's top military intelligence command experienced a leak, risking the exposure of sensitive information to North Korea.
moresecurity-breach

BMW security lapse exposed sensitive company information, researcher finds | TechCrunch

A misconfigured cloud storage server belonging to BMW exposed sensitive company information
The exposed data included private keys, login credentials, and details about other cloud services

Incident Reporting and Response Procedures Policy

The Incident Reporting and Response Procedures Policy from TechRepublic Premium aims to establish a clear process for employees to report security breaches and incidents involving personal devices used for work.
Employees are encouraged to report incidents promptly and are guaranteed whistleblower protection and protection against retaliation for reporting misconduct or negligence.

Stalkerware vendor mSpy breached for a third time

Commercial spyware maker mSpy breached with millions of user data exposed, previously breached in 2015 and 2018.
US Cybersecurity Agency warned of critical vulnerabilities in license management server software, including a CVSS 10.0 vulnerability.
[ Load more ]