#dataexposure — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #dataexposure, aggregated by home.social.
-
Defense Contractor Exposes Military Training Data Through API Flaw
A defense contractor's careless API flaw left sensitive military training data vulnerable, sparking a 152-day saga between the contractor and the open-source security project Strix that ultimately led to the exposure being patched. The breach was caused by a low-privilege account having broad access to user records and…
#ApiSecurity #MilitaryTraining #DefenseContractor #DataExposure #EmergingThreats
-
Voter Data Exposes Personal Info to Potential Abuse
Your voter data is at risk of being exposed and used against you, with publicly available registration files potentially revealing sensitive information about you and your family. Even redacted files can be easily linked to other public datasets, making it simple for employers, fraud rings, or others to access your personal info.
#VoterDataSecurity #DataExposure #IdentityDisclosure #PublicRecords #Reidentification
-
CareCloud says one EHR environment hit in New Jersey #CareCloud #EHR #UnauthorizedAccess #NewJersey #SEC #DataExposure https://dysruptionhub.com/carecloud-ehr-outage-new-jersey/
-
CareCloud says one EHR environment hit in New Jersey #CareCloud #EHR #UnauthorizedAccess #NewJersey #SEC #DataExposure https://dysruptionhub.com/carecloud-ehr-outage-new-jersey/
-
Incident summary:
Target: PayPal - Working Capital (PPWC) loan app
Root cause: Software code error
Exposure window: July 1- Dec 13, 2025
Discovery: Dec 12, 2025
Scope: ~100 usersData exposed:
• SSN
• DOB
• Contact & business detailsNo core system compromise reported.
Unauthorized transactions observed in limited cases.Credit monitoring via Equifax provided.
Key considerations:– Secure SDLC gaps?
– Change management review failure?
– Logging & anomaly detection delay?
– Exposure vs intrusion classification challengesSix months of unnoticed PII exposure highlights how application-layer misconfigurations can rival full breaches in impact.
How would you design detection controls to catch this earlier?
Engage below.
Follow @technadu for technical cybersecurity coverage.#ThreatAnalysis #SecureSDLC #FintechSecurity #ApplicationSecurity #DataExposure #CyberRisk #DFIR #Governance #Infosec
-
Incident summary:
Target: PayPal - Working Capital (PPWC) loan app
Root cause: Software code error
Exposure window: July 1- Dec 13, 2025
Discovery: Dec 12, 2025
Scope: ~100 usersData exposed:
• SSN
• DOB
• Contact & business detailsNo core system compromise reported.
Unauthorized transactions observed in limited cases.Credit monitoring via Equifax provided.
Key considerations:– Secure SDLC gaps?
– Change management review failure?
– Logging & anomaly detection delay?
– Exposure vs intrusion classification challengesSix months of unnoticed PII exposure highlights how application-layer misconfigurations can rival full breaches in impact.
How would you design detection controls to catch this earlier?
Engage below.
Follow @technadu for technical cybersecurity coverage.#ThreatAnalysis #SecureSDLC #FintechSecurity #ApplicationSecurity #DataExposure #CyberRisk #DFIR #Governance #Infosec
-
Incident summary:
Target: PayPal - Working Capital (PPWC) loan app
Root cause: Software code error
Exposure window: July 1- Dec 13, 2025
Discovery: Dec 12, 2025
Scope: ~100 usersData exposed:
• SSN
• DOB
• Contact & business detailsNo core system compromise reported.
Unauthorized transactions observed in limited cases.Credit monitoring via Equifax provided.
Key considerations:– Secure SDLC gaps?
– Change management review failure?
– Logging & anomaly detection delay?
– Exposure vs intrusion classification challengesSix months of unnoticed PII exposure highlights how application-layer misconfigurations can rival full breaches in impact.
How would you design detection controls to catch this earlier?
Engage below.
Follow @technadu for technical cybersecurity coverage.#ThreatAnalysis #SecureSDLC #FintechSecurity #ApplicationSecurity #DataExposure #CyberRisk #DFIR #Governance #Infosec
-
Incident summary:
Target: PayPal - Working Capital (PPWC) loan app
Root cause: Software code error
Exposure window: July 1- Dec 13, 2025
Discovery: Dec 12, 2025
Scope: ~100 usersData exposed:
• SSN
• DOB
• Contact & business detailsNo core system compromise reported.
Unauthorized transactions observed in limited cases.Credit monitoring via Equifax provided.
Key considerations:– Secure SDLC gaps?
– Change management review failure?
– Logging & anomaly detection delay?
– Exposure vs intrusion classification challengesSix months of unnoticed PII exposure highlights how application-layer misconfigurations can rival full breaches in impact.
How would you design detection controls to catch this earlier?
Engage below.
Follow @technadu for technical cybersecurity coverage.#ThreatAnalysis #SecureSDLC #FintechSecurity #ApplicationSecurity #DataExposure #CyberRisk #DFIR #Governance #Infosec
-
ShinyHunters has listed a 1.67 GB JSON dataset allegedly containing 600K+ customer records tied to Canada Goose.
Reported by BleepingComputer.Dataset reportedly includes:
• checkout_id, cart_token schema indicators
• Shipping lines & order values
• IP telemetry
• Device/browser metadata
• Partial PAN (BIN + last four)
• Authorization metadata
No full card numbers observed in samples.Canada Goose states no evidence of breach of its own systems; attackers claim third-party processor origin.
Security implications:
• BIN + last four enable targeted card fraud attempts
• Order value profiling identifies high-value targets
• IP/device metadata aids social engineering
• Historical datasets still carry active fraud potential
Is vendor risk management keeping pace with SaaS-based commerce stacks?Engage below.
Follow @technadu for advanced threat analysis.#ThreatIntel #DataLeak #VendorRisk #RetailSecurity #FraudPrevention #Infosec #CloudSecurity #DataExposure #ShinyHunters #CyberDefense #PrivacyEngineering
-
ShinyHunters has listed a 1.67 GB JSON dataset allegedly containing 600K+ customer records tied to Canada Goose.
Reported by BleepingComputer.Dataset reportedly includes:
• checkout_id, cart_token schema indicators
• Shipping lines & order values
• IP telemetry
• Device/browser metadata
• Partial PAN (BIN + last four)
• Authorization metadata
No full card numbers observed in samples.Canada Goose states no evidence of breach of its own systems; attackers claim third-party processor origin.
Security implications:
• BIN + last four enable targeted card fraud attempts
• Order value profiling identifies high-value targets
• IP/device metadata aids social engineering
• Historical datasets still carry active fraud potential
Is vendor risk management keeping pace with SaaS-based commerce stacks?Engage below.
Follow @technadu for advanced threat analysis.#ThreatIntel #DataLeak #VendorRisk #RetailSecurity #FraudPrevention #Infosec #CloudSecurity #DataExposure #ShinyHunters #CyberDefense #PrivacyEngineering
-
ShinyHunters has listed a 1.67 GB JSON dataset allegedly containing 600K+ customer records tied to Canada Goose.
Reported by BleepingComputer.Dataset reportedly includes:
• checkout_id, cart_token schema indicators
• Shipping lines & order values
• IP telemetry
• Device/browser metadata
• Partial PAN (BIN + last four)
• Authorization metadata
No full card numbers observed in samples.Canada Goose states no evidence of breach of its own systems; attackers claim third-party processor origin.
Security implications:
• BIN + last four enable targeted card fraud attempts
• Order value profiling identifies high-value targets
• IP/device metadata aids social engineering
• Historical datasets still carry active fraud potential
Is vendor risk management keeping pace with SaaS-based commerce stacks?Engage below.
Follow @technadu for advanced threat analysis.#ThreatIntel #DataLeak #VendorRisk #RetailSecurity #FraudPrevention #Infosec #CloudSecurity #DataExposure #ShinyHunters #CyberDefense #PrivacyEngineering
-
ShinyHunters has listed a 1.67 GB JSON dataset allegedly containing 600K+ customer records tied to Canada Goose.
Reported by BleepingComputer.Dataset reportedly includes:
• checkout_id, cart_token schema indicators
• Shipping lines & order values
• IP telemetry
• Device/browser metadata
• Partial PAN (BIN + last four)
• Authorization metadata
No full card numbers observed in samples.Canada Goose states no evidence of breach of its own systems; attackers claim third-party processor origin.
Security implications:
• BIN + last four enable targeted card fraud attempts
• Order value profiling identifies high-value targets
• IP/device metadata aids social engineering
• Historical datasets still carry active fraud potential
Is vendor risk management keeping pace with SaaS-based commerce stacks?Engage below.
Follow @technadu for advanced threat analysis.#ThreatIntel #DataLeak #VendorRisk #RetailSecurity #FraudPrevention #Infosec #CloudSecurity #DataExposure #ShinyHunters #CyberDefense #PrivacyEngineering
-
Two billion email addresses were exposed
#HackerNews #emailbreach #dataexposure #cybersecurity #privacy #awareness
-
South Carolinas Dillon County probes possible hack #DillonCounty #SouthCarolina #NetworkDisruption #ForensicInvestigation #LawEnforcement #DataExposure #Cyberattack https://dysruptionhub.com/dillon-county-sc-possible-hack/
-
South Carolinas Dillon County probes possible hack #DillonCounty #SouthCarolina #NetworkDisruption #ForensicInvestigation #LawEnforcement #DataExposure #Cyberattack https://dysruptionhub.com/dillon-county-sc-possible-hack/
-
South Carolinas Dillon County probes possible hack #DillonCounty #SouthCarolina #NetworkDisruption #ForensicInvestigation #LawEnforcement #DataExposure #Cyberattack https://dysruptionhub.com/dillon-county-sc-possible-hack/
-
South Carolinas Dillon County probes possible hack #DillonCounty #SouthCarolina #NetworkDisruption #ForensicInvestigation #LawEnforcement #DataExposure #Cyberattack https://dysruptionhub.com/dillon-county-sc-possible-hack/
-
4TB and no client or personal data eh? 👏🏻
https://infosec.exchange/@technadu/115475109972392589 - A 4TB SQL Server backup tied to EY was exposed on Microsoft Azure, discovered by Neo Security during an asset mapping scan.
EY remediated promptly, confirming no client or personal data was affected.
#CyberSecurity #EY #DataExposure #Azure #Infosec #ThreatIntel #DataProtection #CloudSecurity
-
A 4TB SQL Server backup tied to EY was exposed on Microsoft Azure, discovered by Neo Security during an asset mapping scan.
The file’s naming pattern and metadata indicated it was a full unencrypted database dump - a critical visibility gap in cloud storage hygiene.
EY remediated promptly, confirming no client or personal data was affected.
As botnets continuously scan public cloud assets, how can enterprises proactively detect these exposures before attackers do?
💬 Join the discussion & follow @technadu for deeper security intelligence.
#CyberSecurity #EY #DataExposure #Azure #Infosec #ThreatIntel #DataProtection #CloudSecurity
-
Event startup Partiful wasn’t stripping GPS locations from user-uploaded photos
-
McDonald’s Data Exposed in Third-Party Partner Breach https://dailydarkweb.net/mcdonalds-data-exposed-in-third-party-partner-breach/ #supplychainattack #thirdpartybreach #CyberSecurity #DataBreaches #dataexposure #UnitedStates #McDonalds #dataleak #McD
-
🚨 CVE-2025-49870: High-risk SQLi in WordPress Paid Membership Subscriptions plugin (10K+ sites).
✅ Fixed in v2.15.2
❌ Exploitable without login
💥 Attackers could query or tamper with DB data
Still shocking to see SQL injection so prevalent in 2025.
💬 Are devs overlooking basics, or is plugin culture the real issue?
🔔 Follow @technadu for more threat intel.#WordPress #SQLInjection #Vulnerability #PluginSecurity #WebSecurity #DataExposure #CMSecurity
-
🚨 CVE-2025-49870: High-risk SQLi in WordPress Paid Membership Subscriptions plugin (10K+ sites).
✅ Fixed in v2.15.2
❌ Exploitable without login
💥 Attackers could query or tamper with DB data
Still shocking to see SQL injection so prevalent in 2025.
💬 Are devs overlooking basics, or is plugin culture the real issue?
🔔 Follow @technadu for more threat intel.#WordPress #SQLInjection #Vulnerability #PluginSecurity #WebSecurity #DataExposure #CMSecurity
-
🚨 Security researcher finds 1,300+ exposed TeslaMate servers leaking
Tesla data — from trip locations to charging times.⚡ “You’re unintentionally sharing your car’s movements with the world.” – Seyfullah Kiliç, SwordSec
💬 Who’s responsible — open-source devs or end-users? -
Flaws in Software Used by Hundreds of Cities and Towns Exposed Sensitive Data – Source: www.securityweek.com https://ciso2ciso.com/flaws-in-software-used-by-hundreds-of-cities-and-towns-exposed-sensitive-data-source-www-securityweek-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #vulnerabilities #securityweekcom #Vulnerability #DataExposure #securityweek #Workhorse
-
Flaws in Software Used by Hundreds of Cities and Towns Exposed Sensitive Data https://www.securityweek.com/flaws-in-software-used-by-hundreds-of-cities-and-towns-exposed-sensitive-data/ #Vulnerabilities #vulnerability #DataExposure #Workhorse
-
Flaws in Software Used by Hundreds of Cities and Towns Exposed Sensitive Data https://www.securityweek.com/flaws-in-software-used-by-hundreds-of-cities-and-towns-exposed-sensitive-data/ #Vulnerabilities #vulnerability #DataExposure #Workhorse
-
Major Enterprise AI Assistants Can Be Abused for Data Theft, Manipulation https://www.securityweek.com/major-enterprise-ai-assistants-abused-for-data-theft-manipulation/ #ArtificialIntelligence #DataExposure #ChatGPT #Copilot #Cursor #Gemini #AI
-
Major Enterprise AI Assistants Can Be Abused for Data Theft, Manipulation https://www.securityweek.com/major-enterprise-ai-assistants-abused-for-data-theft-manipulation/ #ArtificialIntelligence #DataExposure #ChatGPT #Copilot #Cursor #Gemini #AI
-
Alleged Data Exposure Hits Indonesian Supreme Court https://dailydarkweb.net/alleged-data-exposure-hits-indonesian-supreme-court/ #DarkWebNews&Services #MAHKAMAHAGUNGGOID #governmentdata #CyberSecurity #MAHKAMAHAGUNG #dataexposure #SupremeCourt #databreach #Indonesia
-
Alleged Data Exposure Hits Indonesian Supreme Court https://dailydarkweb.net/alleged-data-exposure-hits-indonesian-supreme-court/ #DarkWebNews&Services #MAHKAMAHAGUNGGOID #governmentdata #CyberSecurity #MAHKAMAHAGUNG #dataexposure #SupremeCourt #databreach #Indonesia
-
Alleged Data Exposure Hits Indonesian Supreme Court https://dailydarkweb.net/alleged-data-exposure-hits-indonesian-supreme-court/ #DarkWebNews&Services #MAHKAMAHAGUNGGOID #governmentdata #CyberSecurity #MAHKAMAHAGUNG #dataexposure #SupremeCourt #databreach #Indonesia
-
Alleged Data Exposure Hits Indonesian Supreme Court https://dailydarkweb.net/alleged-data-exposure-hits-indonesian-supreme-court/ #DarkWebNews&Services #MAHKAMAHAGUNGGOID #governmentdata #CyberSecurity #MAHKAMAHAGUNG #dataexposure #SupremeCourt #databreach #Indonesia
-
Alleged Breach of Everest Bank Customer Database https://dailydarkweb.net/alleged-breach-of-everest-bank-customer-database/ #PersonalInformation #BankingSecurity #CyberSecurity #DataBreaches #customerdata #dataexposure #EverestBank #databreach #India
-
Alleged Breach of Everest Bank Customer Database https://dailydarkweb.net/alleged-breach-of-everest-bank-customer-database/ #PersonalInformation #BankingSecurity #CyberSecurity #DataBreaches #customerdata #dataexposure #EverestBank #databreach #India
-
Alleged Breach of Everest Bank Customer Database https://dailydarkweb.net/alleged-breach-of-everest-bank-customer-database/ #PersonalInformation #BankingSecurity #CyberSecurity #DataBreaches #customerdata #dataexposure #EverestBank #databreach #India
-
Alleged Breach of Everest Bank Customer Database https://dailydarkweb.net/alleged-breach-of-everest-bank-customer-database/ #PersonalInformation #BankingSecurity #CyberSecurity #DataBreaches #customerdata #dataexposure #EverestBank #databreach #India
-
In a penetration test, automated tools find known vulnerabilities—but they don’t think like an attacker...
You can absolutely automate the 'vulnerability assessment' phase and information discovery.It’s possible to automate some exploitation too, if you’re brave and don’t care about the stability of the customer’s network.
However, humans perform penetration testing.Here's a story that illustrates why: https://www.pentestpartners.com/security-blog/a-tale-of-enumeration-and-why-pen-testing-cant-be-automated/
#CyberSecurity #PenTesting #EthicalHacking #OSINT #DataExposure #InfoSec #AutomatedTesting #InfrastructureSecurity
-
Hello everyone.
In today's article we are reviewing shodan for beginners.
I wish everyone good work and reading.
https://denizhalil.com/2025/01/06/shodan-search-engine-cybersecurity-guide/
#cybersecurity #shodan #penetrationtesting #shodancheatsheet #networksecurity #ethicalhacking #dataexposure
-
Over 600,000 Personal Records Exposed by Data Broker – Source: www.techrepublic.com https://ciso2ciso.com/over-600000-personal-records-exposed-by-data-broker-source-www-techrepublic-com/ #rssfeedpostgeneratorecho #SecurityonTechRepublic #SecurityTechRepublic #CyberSecurityNews #cybersecurity #Cybersecurity #DataExposure #Security
-
Signal under fire for storing encryption keys in plaintext
https://stackdiary.com/signal-under-fire-for-storing-encryption-keys-in-plaintext/
#Signal #Privacy #Encryption #Cybersecurity #Messaging #DataProtection #SecureComms #DesktopApp #Vulnerability #InfoSec #DigitalSecurity #EndToEnd #PlainText #KeyManagement #TechNews #PrivacyBreach #SecurityAlert #Cryptography #DataSafety #MobileApps #UserPrivacy #SecurityFlaw #EncryptionKeys #Tech #MessageSecurity #PrivacyRisk #SecureMessaging #CyberRisk #DataExposure
-
Signal under fire for storing encryption keys in plaintext
https://stackdiary.com/signal-under-fire-for-storing-encryption-keys-in-plaintext/
#Signal #Privacy #Encryption #Cybersecurity #Messaging #DataProtection #SecureComms #DesktopApp #Vulnerability #InfoSec #DigitalSecurity #EndToEnd #PlainText #KeyManagement #TechNews #PrivacyBreach #SecurityAlert #Cryptography #DataSafety #MobileApps #UserPrivacy #SecurityFlaw #EncryptionKeys #Tech #MessageSecurity #PrivacyRisk #SecureMessaging #CyberRisk #DataExposure
-
Signal under fire for storing encryption keys in plaintext
https://stackdiary.com/signal-under-fire-for-storing-encryption-keys-in-plaintext/
#Signal #Privacy #Encryption #Cybersecurity #Messaging #DataProtection #SecureComms #DesktopApp #Vulnerability #InfoSec #DigitalSecurity #EndToEnd #PlainText #KeyManagement #TechNews #PrivacyBreach #SecurityAlert #Cryptography #DataSafety #MobileApps #UserPrivacy #SecurityFlaw #EncryptionKeys #Tech #MessageSecurity #PrivacyRisk #SecureMessaging #CyberRisk #DataExposure
-
Signal under fire for storing encryption keys in plaintext
https://stackdiary.com/signal-under-fire-for-storing-encryption-keys-in-plaintext/
#Signal #Privacy #Encryption #Cybersecurity #Messaging #DataProtection #SecureComms #DesktopApp #Vulnerability #InfoSec #DigitalSecurity #EndToEnd #PlainText #KeyManagement #TechNews #PrivacyBreach #SecurityAlert #Cryptography #DataSafety #MobileApps #UserPrivacy #SecurityFlaw #EncryptionKeys #Tech #MessageSecurity #PrivacyRisk #SecureMessaging #CyberRisk #DataExposure
-
Signal under fire for storing encryption keys in plaintext
https://stackdiary.com/signal-under-fire-for-storing-encryption-keys-in-plaintext/
#Signal #Privacy #Encryption #Cybersecurity #Messaging #DataProtection #SecureComms #DesktopApp #Vulnerability #InfoSec #DigitalSecurity #EndToEnd #PlainText #KeyManagement #TechNews #PrivacyBreach #SecurityAlert #Cryptography #DataSafety #MobileApps #UserPrivacy #SecurityFlaw #EncryptionKeys #Tech #MessageSecurity #PrivacyRisk #SecureMessaging #CyberRisk #DataExposure
-
Azure Service Tags Vulnerability Controversy
Date: June 2024
CVE: N/A
Vulnerability Type: Security Misconfiguration
CWE: [[CWE-20]], [[CWE-287]]
Sources: Bleeping ComputerSynopsis
A security vulnerability in Azure Service Tags has been highlighted by Tenable, who identified a risk of data exposure due to how Service Tags handle firewall rules and access control. Microsoft, however, disputes this assessment, clarifying the intended use of Service Tags.
Issue Summary
Tenable's security researchers claim that they discovered a high-severity vulnerability in Azure Service Tags that allows attackers to impersonate trusted Azure services and bypass firewall rules based on Azure Service Tags, and can access private data that way by crafting SSRF-like web requests. These tags, designed for routing and not security boundaries -as per Microsoft-, can be manipulated to impersonate trusted services and access sensitive data.
Technical Key findings
The vulnerability exploits the "availability test" feature within Azure's Application Insights Availability service. By manipulating custom headers and HTTP requests, attackers can bypass network controls that rely on Service Tags, thus accessing internal services and APIs hosted on common ports (80/443).
Vulnerable Products
- Azure DevOps
- Azure Machine Learning
- Azure Logic Apps
- Azure Container Registry
- Azure Load Testing
- Azure API Management
- Azure Data Factory
- Azure Action Group
- Azure AI Video Indexer
- Azure Chaos Studio
Impact Assessment
Exploitation of this vulnerability could lead to unauthorized access to sensitive data and internal APIs, potentially exposing internal services to malicious actors. This represents a significant risk, particularly for services relying solely on Service Tags for security.
Patches or Workaround
Microsoft has not issued a patch, asserting that Service Tags are not designed as a security boundary. They recommend adding authentication and authorization layers to enhance security. Azure customers should follow Microsoft's updated guidelines and review their network configurations to ensure robust security measures are in place.
Tags
#Azure #ServiceTags #Vulnerability #SSRF #DataExposure #CloudSecurity #Microsoft #FirewallBypass
-
Potential personal data exposure on LHDN’s payment portal #cybersecurity #databreach #dataexposure #dataprotection #digitallife #featured #inlandrevenueboard #irb #lhdn #news #security
https://soyacincau.com/2023/12/13/lhdn-irb-data-exposure-payment-portal-slip/
-
"🚨 Critical Flaws in Citrix NetScaler Expose Data & Enable DoS Attacks 🚨"
Citrix NetScaler has been hit with two critical vulnerabilities, CVE-2023-4966 and CVE-2023-4967, exposing sensitive data and enabling DoS attacks. The former, with a CVSS score of 9.4, allows remote exploitation without high-level access, while the latter, scoring 8.2, enables a Denial of Service attack on vulnerable devices. Citrix has rolled out security upgrades, urging customers to update to safeguard their systems. 🛡️🌐
CVE-2023-4966: This one's pretty severe and could allow unauthorized access to sensitive data without needing high-level access or user involvement.
CVE-2023-4967: Another biggie, this could enable a ‘Denial of Service attack’, basically shutting down our systems.Source: GBHackers by Divya
Tags: #Citrix #NetScaler #Vulnerability #CyberSecurity #DataExposure #DoSAttack #CVE20234966 #CVE20234967 #CyberAttack #InfoSec
-
Look at the datasets available according to this article. They look ripe for abuse and bigotry. #23AndMe #UserData #DataExposure https://therecord.media/scraping-incident-genetic-testing-site
-
@douglevin They claim “no data or information was exposed or compromised during this event."
Diachenko had posted a redacted screenshot on X
(see https://twitter.com/MayhemDayOne/status/1694311872827208160/photo/1) showing that personal information was exposed, so the firm's denial of any exposure seems.... factually inaccurate, to say the least.Similarly, their statement that "Our technical team promptly resolved this issue as soon as it came to our notice." does not explain why they didn't notice it sooner when Diachenko first reached out to them to alert them. He went public because they didn't "notice" or respond timely while personal information was reportedly exposed.
This company does not seem very credible in their claims with respect to this incident.
And they also seem to be in a lot of financial distress even prior to this incident: https://www.bbc.com/news/world-asia-india-66126095
#EdTech #Misconfiguration #DataExposure #IncidentResponse #EduSec