#dataexposure — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #dataexposure, aggregated by home.social.
-
🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.
What's exposed:
- Creator emails, conference IDs, recording status, timestamps
- Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
- Government meetings from 23 countries
- Corporate meetings from thousands of companies
Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.
Full writeup: https://bobdahacker.com/blog/tldv-hack
#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy
-
🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.
What's exposed:
- Creator emails, conference IDs, recording status, timestamps
- Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
- Government meetings from 23 countries
- Corporate meetings from thousands of companies
Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.
Full writeup: https://bobdahacker.com/blog/tldv-hack
#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy
-
🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.
What's exposed:
- Creator emails, conference IDs, recording status, timestamps
- Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
- Government meetings from 23 countries
- Corporate meetings from thousands of companies
Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.
Full writeup: https://bobdahacker.com/blog/tldv-hack
#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy
-
🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.
What's exposed:
- Creator emails, conference IDs, recording status, timestamps
- Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
- Government meetings from 23 countries
- Corporate meetings from thousands of companies
Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.
Full writeup: https://bobdahacker.com/blog/tldv-hack
#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy
-
🍝 New Blog Post: tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
tl;dv's Firestore database has zero tenant isolation on their meetings collection. Any free-tier user can query every meeting on the platform. 181,874 meetings. 84,312 users. 35,003 domains.
What's exposed:
- Creator emails, conference IDs, recording status, timestamps
- Live calls you can join uninvited (I joined 2, including one with the Malaysian Ministry of Education)
- Government meetings from 23 countries
- Corporate meetings from thousands of companies
Reported January 28th. Six months later, still not fixed. CTO never responded. Their Firestore database has better uptime than their inbox.
Full writeup: https://bobdahacker.com/blog/tldv-hack
#InfoSec #BugBounty #ResponsibleDisclosure #Firebase #Security #CyberSecurity #Privacy #DataExposure #APISecurity #tldv #MeetingPrivacy
-
https://www.europesays.com/ie/610299/ PSA: Your Claude shared chats and Artifacts may have ended up on Google #AI #Anthropic #ArtificialIntelligence #ArtificialIntelligence #claude #DataExposure #Éire #IE #Ireland #Technology
-
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
-
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
-
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
-
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
-
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: https://bobdahacker.com/blog/click-to-pray
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
-
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
https://web.brid.gy/r/https://bobdahacker.com/blog/click-to-pray
-
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
https://web.brid.gy/r/https://bobdahacker.com/blog/click-to-pray
-
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
https://web.brid.gy/r/https://bobdahacker.com/blog/click-to-pray
-
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
https://web.brid.gy/r/https://bobdahacker.com/blog/click-to-pray
-
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
https://web.brid.gy/r/https://bobdahacker.com/blog/click-to-pray
-
LAPD lets contract with surveillance giant Flock expire, citing ‘serious concerns’ over civil liberties and privacy
The Los Angeles Police Department (LAPD) is reportedly ending its deal with Flock Safety, a surveillance company that…
#NewsBeep #News #Headlines #cybersecurity #dataexposure #Flock #LAPD #Privacy #surveillance #UnitedStates #Us #USA
https://www.newsbeep.com/642022/ -
🟡 Cyber Incident | 7/10
🇺🇸Data exposure at Peter Thiel-linked Dialog network
A misconfigured website exposed personal details and login tokens of 222 registrants, including a senior White House intelligence official and an active-duty Tier 1 intelligence officer. The Pentagon is investigating the breach.#OSINT #NewsGroup #CyberIncident #DataExposure #Pentagon #US
-
🟡 Cyber Incident | 7/10
🇺🇸Data exposure at Peter Thiel-linked Dialog network
A misconfigured website exposed personal details and login tokens of 222 registrants, including a senior White House intelligence official and an active-duty Tier 1 intelligence officer. The Pentagon is investigating the breach.#OSINT #NewsGroup #CyberIncident #DataExposure #Pentagon #US
-
🟡 Cyber Incident | 7/10
🇺🇸Data exposure at Peter Thiel-linked Dialog network
A misconfigured website exposed personal details and login tokens of 222 registrants, including a senior White House intelligence official and an active-duty Tier 1 intelligence officer. The Pentagon is investigating the breach.#OSINT #NewsGroup #CyberIncident #DataExposure #Pentagon #US
-
🟡 Cyber Incident | 7/10
🇺🇸Data exposure at Peter Thiel-linked Dialog network
A misconfigured website exposed personal details and login tokens of 222 registrants, including a senior White House intelligence official and an active-duty Tier 1 intelligence officer. The Pentagon is investigating the breach.#OSINT #NewsGroup #CyberIncident #DataExposure #Pentagon #US
-
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
-
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
-
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
-
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
-
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure
-
https://www.europesays.com/ie/528239/ ServiceNow tells customers a bug left some of their data exposed to the internet #Cybersecurity #DataExposure #Éire #IE #Ireland #ServiceNow #Technology
-
CEO's File Share Mishap Exposes Workplace Security Lapses
Imagine being called in to help a CEO recover deleted files, only to discover a shocking secret: a treasure trove of explicit content stored on a company file share that's accessible to anyone. The awkward moment that followed will leave you cringing - and wondering how something so sensitive could be so carelessly exposed.
#DataExposure #WorkplaceSecurity #FileShare #InsiderThreats #Ceo
-
Trump Mobile Website Exposed Thousands of User Records
A shocking security lapse has been uncovered on the Trump Mobile website, allegedly exposing thousands of users' sensitive information, according to a report by The Register. The breach claim, made by a techie, raises serious concerns about the website's data protection measures.
#DataExposure #TrumpMobile #EmergingThreats #UserDataLeak #WebsiteSecurity
-
Belgrade, Montana, schools restoring systems after malware disruption #Malware #DataExposure #InfiniteCampus #SchoolDistrict #Cybersecurity #Montana https://dysruptionhub.com/belgrade-montana-school-malware/
-
Belgrade, Montana, schools restoring systems after malware disruption #Malware #DataExposure #InfiniteCampus #SchoolDistrict #Cybersecurity #Montana https://dysruptionhub.com/belgrade-montana-school-malware/
-
UK Water Supplier Fined $1.3M for Data Exposure Lapse
A UK water supplier has been slapped with a $1.3 million fine after a devastating cyber attack exposed the personal data of nearly 664,000 customers and employees, with sensitive information even being published on the dark web. The hefty penalty was reduced by 40% after the company admitted liability and cooperated with investigators.
#DataExposure #Uk #WaterSector #EmergingThreats #InformationCommissionersOffice
-
Defense Contractor Exposes Military Training Data Through API Flaw
A defense contractor's careless API flaw left sensitive military training data vulnerable, sparking a 152-day saga between the contractor and the open-source security project Strix that ultimately led to the exposure being patched. The breach was caused by a low-privilege account having broad access to user records and…
#ApiSecurity #MilitaryTraining #DefenseContractor #DataExposure #EmergingThreats
-
Voter Data Exposes Personal Info to Potential Abuse
Your voter data is at risk of being exposed and used against you, with publicly available registration files potentially revealing sensitive information about you and your family. Even redacted files can be easily linked to other public datasets, making it simple for employers, fraud rings, or others to access your personal info.
#VoterDataSecurity #DataExposure #IdentityDisclosure #PublicRecords #Reidentification
-
AI Agents Fuel Cybersecurity Breaches at Most Firms
As AI agents increasingly power business operations, they're also fueling cybersecurity breaches at most firms, leading to data exposure, operational disruption, and financial losses. The rapid rise of AI is sparking a pressing dilemma: how can organizations balance innovation with control?
#CloudSecurity #AiAgents #CybersecurityBreaches #DataExposure #OperationalDisruption
-
CareCloud says one EHR environment hit in New Jersey #CareCloud #EHR #UnauthorizedAccess #NewJersey #SEC #DataExposure https://dysruptionhub.com/carecloud-ehr-outage-new-jersey/
-
CareCloud says one EHR environment hit in New Jersey #CareCloud #EHR #UnauthorizedAccess #NewJersey #SEC #DataExposure https://dysruptionhub.com/carecloud-ehr-outage-new-jersey/
-
Incident summary:
Target: PayPal - Working Capital (PPWC) loan app
Root cause: Software code error
Exposure window: July 1- Dec 13, 2025
Discovery: Dec 12, 2025
Scope: ~100 usersData exposed:
• SSN
• DOB
• Contact & business detailsNo core system compromise reported.
Unauthorized transactions observed in limited cases.Credit monitoring via Equifax provided.
Key considerations:– Secure SDLC gaps?
– Change management review failure?
– Logging & anomaly detection delay?
– Exposure vs intrusion classification challengesSix months of unnoticed PII exposure highlights how application-layer misconfigurations can rival full breaches in impact.
How would you design detection controls to catch this earlier?
Engage below.
Follow @technadu for technical cybersecurity coverage.#ThreatAnalysis #SecureSDLC #FintechSecurity #ApplicationSecurity #DataExposure #CyberRisk #DFIR #Governance #Infosec
-
Incident summary:
Target: PayPal - Working Capital (PPWC) loan app
Root cause: Software code error
Exposure window: July 1- Dec 13, 2025
Discovery: Dec 12, 2025
Scope: ~100 usersData exposed:
• SSN
• DOB
• Contact & business detailsNo core system compromise reported.
Unauthorized transactions observed in limited cases.Credit monitoring via Equifax provided.
Key considerations:– Secure SDLC gaps?
– Change management review failure?
– Logging & anomaly detection delay?
– Exposure vs intrusion classification challengesSix months of unnoticed PII exposure highlights how application-layer misconfigurations can rival full breaches in impact.
How would you design detection controls to catch this earlier?
Engage below.
Follow @technadu for technical cybersecurity coverage.#ThreatAnalysis #SecureSDLC #FintechSecurity #ApplicationSecurity #DataExposure #CyberRisk #DFIR #Governance #Infosec
-
Incident summary:
Target: PayPal - Working Capital (PPWC) loan app
Root cause: Software code error
Exposure window: July 1- Dec 13, 2025
Discovery: Dec 12, 2025
Scope: ~100 usersData exposed:
• SSN
• DOB
• Contact & business detailsNo core system compromise reported.
Unauthorized transactions observed in limited cases.Credit monitoring via Equifax provided.
Key considerations:– Secure SDLC gaps?
– Change management review failure?
– Logging & anomaly detection delay?
– Exposure vs intrusion classification challengesSix months of unnoticed PII exposure highlights how application-layer misconfigurations can rival full breaches in impact.
How would you design detection controls to catch this earlier?
Engage below.
Follow @technadu for technical cybersecurity coverage.#ThreatAnalysis #SecureSDLC #FintechSecurity #ApplicationSecurity #DataExposure #CyberRisk #DFIR #Governance #Infosec
-
Incident summary:
Target: PayPal - Working Capital (PPWC) loan app
Root cause: Software code error
Exposure window: July 1- Dec 13, 2025
Discovery: Dec 12, 2025
Scope: ~100 usersData exposed:
• SSN
• DOB
• Contact & business detailsNo core system compromise reported.
Unauthorized transactions observed in limited cases.Credit monitoring via Equifax provided.
Key considerations:– Secure SDLC gaps?
– Change management review failure?
– Logging & anomaly detection delay?
– Exposure vs intrusion classification challengesSix months of unnoticed PII exposure highlights how application-layer misconfigurations can rival full breaches in impact.
How would you design detection controls to catch this earlier?
Engage below.
Follow @technadu for technical cybersecurity coverage.#ThreatAnalysis #SecureSDLC #FintechSecurity #ApplicationSecurity #DataExposure #CyberRisk #DFIR #Governance #Infosec
-
ShinyHunters has listed a 1.67 GB JSON dataset allegedly containing 600K+ customer records tied to Canada Goose.
Reported by BleepingComputer.Dataset reportedly includes:
• checkout_id, cart_token schema indicators
• Shipping lines & order values
• IP telemetry
• Device/browser metadata
• Partial PAN (BIN + last four)
• Authorization metadata
No full card numbers observed in samples.Canada Goose states no evidence of breach of its own systems; attackers claim third-party processor origin.
Security implications:
• BIN + last four enable targeted card fraud attempts
• Order value profiling identifies high-value targets
• IP/device metadata aids social engineering
• Historical datasets still carry active fraud potential
Is vendor risk management keeping pace with SaaS-based commerce stacks?Engage below.
Follow @technadu for advanced threat analysis.#ThreatIntel #DataLeak #VendorRisk #RetailSecurity #FraudPrevention #Infosec #CloudSecurity #DataExposure #ShinyHunters #CyberDefense #PrivacyEngineering
-
ShinyHunters has listed a 1.67 GB JSON dataset allegedly containing 600K+ customer records tied to Canada Goose.
Reported by BleepingComputer.Dataset reportedly includes:
• checkout_id, cart_token schema indicators
• Shipping lines & order values
• IP telemetry
• Device/browser metadata
• Partial PAN (BIN + last four)
• Authorization metadata
No full card numbers observed in samples.Canada Goose states no evidence of breach of its own systems; attackers claim third-party processor origin.
Security implications:
• BIN + last four enable targeted card fraud attempts
• Order value profiling identifies high-value targets
• IP/device metadata aids social engineering
• Historical datasets still carry active fraud potential
Is vendor risk management keeping pace with SaaS-based commerce stacks?Engage below.
Follow @technadu for advanced threat analysis.#ThreatIntel #DataLeak #VendorRisk #RetailSecurity #FraudPrevention #Infosec #CloudSecurity #DataExposure #ShinyHunters #CyberDefense #PrivacyEngineering
-
ShinyHunters has listed a 1.67 GB JSON dataset allegedly containing 600K+ customer records tied to Canada Goose.
Reported by BleepingComputer.Dataset reportedly includes:
• checkout_id, cart_token schema indicators
• Shipping lines & order values
• IP telemetry
• Device/browser metadata
• Partial PAN (BIN + last four)
• Authorization metadata
No full card numbers observed in samples.Canada Goose states no evidence of breach of its own systems; attackers claim third-party processor origin.
Security implications:
• BIN + last four enable targeted card fraud attempts
• Order value profiling identifies high-value targets
• IP/device metadata aids social engineering
• Historical datasets still carry active fraud potential
Is vendor risk management keeping pace with SaaS-based commerce stacks?Engage below.
Follow @technadu for advanced threat analysis.#ThreatIntel #DataLeak #VendorRisk #RetailSecurity #FraudPrevention #Infosec #CloudSecurity #DataExposure #ShinyHunters #CyberDefense #PrivacyEngineering
-
ShinyHunters has listed a 1.67 GB JSON dataset allegedly containing 600K+ customer records tied to Canada Goose.
Reported by BleepingComputer.Dataset reportedly includes:
• checkout_id, cart_token schema indicators
• Shipping lines & order values
• IP telemetry
• Device/browser metadata
• Partial PAN (BIN + last four)
• Authorization metadata
No full card numbers observed in samples.Canada Goose states no evidence of breach of its own systems; attackers claim third-party processor origin.
Security implications:
• BIN + last four enable targeted card fraud attempts
• Order value profiling identifies high-value targets
• IP/device metadata aids social engineering
• Historical datasets still carry active fraud potential
Is vendor risk management keeping pace with SaaS-based commerce stacks?Engage below.
Follow @technadu for advanced threat analysis.#ThreatIntel #DataLeak #VendorRisk #RetailSecurity #FraudPrevention #Infosec #CloudSecurity #DataExposure #ShinyHunters #CyberDefense #PrivacyEngineering
-
Substack has disclosed a security incident involving unauthorized access to limited user data, reportedly obtained through scraping activity described by the threat actor as “noisy.”
The company states that credentials and financial information were not affected, and that mitigations were implemented quickly after discovery. Users have been advised to remain cautious of potential phishing attempts.
From an infosec perspective, this incident underscores challenges around detection timing, data exposure via scraping, and post-incident communication.
How should platforms better monitor and respond to large-scale scraping risks?
Source: https://www.securityweek.com/substack-discloses-security-incident-after-hacker-leaks-data/
Engage in the discussion and follow @technadu for measured cybersecurity analysis.
#Infosec #DataExposure #Scraping #IncidentResponse #CyberRisk #TechNadu #SecurityOperations
-
Substack has disclosed a security incident involving unauthorized access to limited user data, reportedly obtained through scraping activity described by the threat actor as “noisy.”
The company states that credentials and financial information were not affected, and that mitigations were implemented quickly after discovery. Users have been advised to remain cautious of potential phishing attempts.
From an infosec perspective, this incident underscores challenges around detection timing, data exposure via scraping, and post-incident communication.
How should platforms better monitor and respond to large-scale scraping risks?
Source: https://www.securityweek.com/substack-discloses-security-incident-after-hacker-leaks-data/
Engage in the discussion and follow @technadu for measured cybersecurity analysis.
#Infosec #DataExposure #Scraping #IncidentResponse #CyberRisk #TechNadu #SecurityOperations
-
Substack has disclosed a security incident involving unauthorized access to limited user data, reportedly obtained through scraping activity described by the threat actor as “noisy.”
The company states that credentials and financial information were not affected, and that mitigations were implemented quickly after discovery. Users have been advised to remain cautious of potential phishing attempts.
From an infosec perspective, this incident underscores challenges around detection timing, data exposure via scraping, and post-incident communication.
How should platforms better monitor and respond to large-scale scraping risks?
Source: https://www.securityweek.com/substack-discloses-security-incident-after-hacker-leaks-data/
Engage in the discussion and follow @technadu for measured cybersecurity analysis.
#Infosec #DataExposure #Scraping #IncidentResponse #CyberRisk #TechNadu #SecurityOperations
-
Substack has disclosed a security incident involving unauthorized access to limited user data, reportedly obtained through scraping activity described by the threat actor as “noisy.”
The company states that credentials and financial information were not affected, and that mitigations were implemented quickly after discovery. Users have been advised to remain cautious of potential phishing attempts.
From an infosec perspective, this incident underscores challenges around detection timing, data exposure via scraping, and post-incident communication.
How should platforms better monitor and respond to large-scale scraping risks?
Source: https://www.securityweek.com/substack-discloses-security-incident-after-hacker-leaks-data/
Engage in the discussion and follow @technadu for measured cybersecurity analysis.
#Infosec #DataExposure #Scraping #IncidentResponse #CyberRisk #TechNadu #SecurityOperations
-
SoundCloud’s December 2025 breach has been added to HIBP, confirming exposure of ~29.8M user accounts.
The incident stemmed from unauthorized access to an internal service dashboard that enabled correlation of email addresses with public profile data. No credentials or financial information were compromised, but the case highlights how internal tooling can expand the attack surface.
What practical controls help reduce correlation risk in large platforms?
Source: https://cyberinsider.com/soundcloud-breach-added-to-hibp-29-8-million-accounts-exposed/Share insights and follow TechNadu for independent InfoSec coverage.
#InfoSec #SoundCloud #HIBP #DataExposure #PrivacyEngineering #CyberRisk #SecurityOperations
-
SoundCloud’s December 2025 breach has been added to HIBP, confirming exposure of ~29.8M user accounts.
The incident stemmed from unauthorized access to an internal service dashboard that enabled correlation of email addresses with public profile data. No credentials or financial information were compromised, but the case highlights how internal tooling can expand the attack surface.
What practical controls help reduce correlation risk in large platforms?
Source: https://cyberinsider.com/soundcloud-breach-added-to-hibp-29-8-million-accounts-exposed/Share insights and follow TechNadu for independent InfoSec coverage.
#InfoSec #SoundCloud #HIBP #DataExposure #PrivacyEngineering #CyberRisk #SecurityOperations
-
SoundCloud’s December 2025 breach has been added to HIBP, confirming exposure of ~29.8M user accounts.
The incident stemmed from unauthorized access to an internal service dashboard that enabled correlation of email addresses with public profile data. No credentials or financial information were compromised, but the case highlights how internal tooling can expand the attack surface.
What practical controls help reduce correlation risk in large platforms?
Source: https://cyberinsider.com/soundcloud-breach-added-to-hibp-29-8-million-accounts-exposed/Share insights and follow TechNadu for independent InfoSec coverage.
#InfoSec #SoundCloud #HIBP #DataExposure #PrivacyEngineering #CyberRisk #SecurityOperations
-
SoundCloud’s December 2025 breach has been added to HIBP, confirming exposure of ~29.8M user accounts.
The incident stemmed from unauthorized access to an internal service dashboard that enabled correlation of email addresses with public profile data. No credentials or financial information were compromised, but the case highlights how internal tooling can expand the attack surface.
What practical controls help reduce correlation risk in large platforms?
Source: https://cyberinsider.com/soundcloud-breach-added-to-hibp-29-8-million-accounts-exposed/Share insights and follow TechNadu for independent InfoSec coverage.
#InfoSec #SoundCloud #HIBP #DataExposure #PrivacyEngineering #CyberRisk #SecurityOperations
-
The reported BreachForums database exposure illustrates a recurring pattern in underground ecosystems: infrastructure weaknesses outweigh perceived anonymity.
Key considerations:
• Metadata remains a critical risk vector
• Forum resilience often masks fragile backends
• Legal and reputational fallout can be long-lastingThis incident reinforces why data minimization and secure configuration matter - regardless of intent or audience.
Source: https://cybersecuritynews.com/breachforums-hack/
Join the discussion and follow @technadu for fact-based cybersecurity reporting.
#InfoSec #ThreatIntel #DarkWeb #DataExposure #CyberRisk #OperationalSecurity
-
The reported BreachForums database exposure illustrates a recurring pattern in underground ecosystems: infrastructure weaknesses outweigh perceived anonymity.
Key considerations:
• Metadata remains a critical risk vector
• Forum resilience often masks fragile backends
• Legal and reputational fallout can be long-lastingThis incident reinforces why data minimization and secure configuration matter - regardless of intent or audience.
Source: https://cybersecuritynews.com/breachforums-hack/
Join the discussion and follow @technadu for fact-based cybersecurity reporting.
#InfoSec #ThreatIntel #DarkWeb #DataExposure #CyberRisk #OperationalSecurity
-
The reported BreachForums database exposure illustrates a recurring pattern in underground ecosystems: infrastructure weaknesses outweigh perceived anonymity.
Key considerations:
• Metadata remains a critical risk vector
• Forum resilience often masks fragile backends
• Legal and reputational fallout can be long-lastingThis incident reinforces why data minimization and secure configuration matter - regardless of intent or audience.
Source: https://cybersecuritynews.com/breachforums-hack/
Join the discussion and follow @technadu for fact-based cybersecurity reporting.
#InfoSec #ThreatIntel #DarkWeb #DataExposure #CyberRisk #OperationalSecurity
-
The reported BreachForums database exposure illustrates a recurring pattern in underground ecosystems: infrastructure weaknesses outweigh perceived anonymity.
Key considerations:
• Metadata remains a critical risk vector
• Forum resilience often masks fragile backends
• Legal and reputational fallout can be long-lastingThis incident reinforces why data minimization and secure configuration matter - regardless of intent or audience.
Source: https://cybersecuritynews.com/breachforums-hack/
Join the discussion and follow @technadu for fact-based cybersecurity reporting.
#InfoSec #ThreatIntel #DarkWeb #DataExposure #CyberRisk #OperationalSecurity
-
Researchers enumerated 3.5B WhatsApp phone numbers through the platform’s contact-discovery feature, revealing public profile photos and text for millions of users. Meta applied rate-limiting after the disclosure and says no non-public data was exposed.
This case raises important questions about phone numbers as identifiers and long-term privacy safeguards.
Share your insights & follow for more security-focused analysis.#InfoSec #CyberSecurity #Privacy #DataExposure #WhatsApp #SecurityResearch #DigitalIdentity #TechNadu
-
Researchers enumerated 3.5B WhatsApp phone numbers through the platform’s contact-discovery feature, revealing public profile photos and text for millions of users. Meta applied rate-limiting after the disclosure and says no non-public data was exposed.
This case raises important questions about phone numbers as identifiers and long-term privacy safeguards.
Share your insights & follow for more security-focused analysis.#InfoSec #CyberSecurity #Privacy #DataExposure #WhatsApp #SecurityResearch #DigitalIdentity #TechNadu
-
Researchers enumerated 3.5B WhatsApp phone numbers through the platform’s contact-discovery feature, revealing public profile photos and text for millions of users. Meta applied rate-limiting after the disclosure and says no non-public data was exposed.
This case raises important questions about phone numbers as identifiers and long-term privacy safeguards.
Share your insights & follow for more security-focused analysis.#InfoSec #CyberSecurity #Privacy #DataExposure #WhatsApp #SecurityResearch #DigitalIdentity #TechNadu