U.S. bank disclose security lapse after sharing customer data with AI app
The bank said the security lapse was due to the use of an “unauthorized” AI software app.
The bank said the security lapse was due to the use of an “unauthorized” AI software app.
An exposed Amazon-hosted server allowed anyone to access reams of customer data without needing a password.
A backend flaw in web admin dashboards used by one of India’s largest pharmacy chains, exposed thousands of online pharmacy orders.
The online mentoring site UStrive exposed email addresses, phone numbers, and other non-public information to other logged-in users. The nonprofit told TechCrunch that the issue is now fixed, but wouldn’t commit to alerting affected individuals.
The phishing campaign targeted users on WhatsApp, including an Iranian-British activist, and stole the credentials of a Lebanese cabinet minister and at least one journalist.
Shipping tech company Bluspark left internal plaintext passwords, including those of executives, exposed to the internet, at a time when hacks in the shipping industry are on the rise.
TechCrunch found Petco’s veterinary clinics were spilling customers’ personal information and medical histories of their pets to the open web.
Petco said the exposure was due to an error in an application, and that it is notifying victims’ whose data was affected.
The pet company has published almost no details about what happened, who was affected, and what personal data was exposed.
TechCrunch verified that the security bug in the Indian Income Tax Department’s e-Filing portal exposed taxpayers’ data to other users. The security researchers who found the flaw say the data leak is now fixed.