Spyke

Posts

Disney hack leads to 1.2TB of Slack communications leaked online

In a significant data breach, hacktivist group NullBulge has infiltrated Disney's internal Slack infrastructure, leaking 1.2TB of sensitive data. This breach, posted on the cybercrime platform Breach Forums on July 12, 2024, exposes many of Disney's internal communications, compromising messages, files, code, and other proprietary information.

Disney hack leads to 1.2TB of Slack communications leaked onlinehttps://stackdiary.com/disney-hack-leads-to-1-2tb-of-slack-communications-leaked-online/Open linkView original on lemmy.world

MSI warranty claim database was publicly accessible via Google

According to the YouTube channel Gamers Nexus, over 600,000 customer warranty claims for MSI products were publicly accessible via Google search. MSI, a leading computer hardware and peripherals manufacturer, had exposed data that included sensitive information such as names, addresses, phone numbers, and specific order details.

MSI warranty claim database was publicly accessible via Googlehttps://stackdiary.com/msi-warranty-claim-database-was-publicly-accessible-via-google/Open linkView original on lemmy.world

IdentifyMobile incident exposed 200M records from hundreds of companies

British bulk SMS provider IdentifyMobile exposed 200M records because a developer misconfigured an AWS S3 bucket and made it public. A research group from Germany spotted the issue and were able to access more than six terabytes of data. The said data included not only SMS message content but also phone numbers, sender names, and sometimes other account information.

Twilio also recently disclosed a security incident in relation to this news, but their alert email completely downplayed the level of data that was available from this AWS bucket.

IdentifyMobile incident exposed 200M records from hundreds of companieshttps://stackdiary.com/identifymobile-incident-exposed-200m-records-from-hundreds-of-companies/Open linkView original on lemmy.world

Linksys Velop routers send Wi-Fi passwords in plaintext to US servers

During installation, the router sent several data packets to an Amazon server in the US. These packets contained the configured SSID name and password in clear text, as well as some identification tokens for this network within a broader database and an access token for a user session that could potentially enable a MITM attack.

Linksys has refused to acknowledge/respond to the issue.

Linksys Velop routers send Wi-Fi passwords in plaintext to US servershttps://stackdiary.com/linksys-velop-routers-send-wi-fi-passwords-in-plaintext-to-us-servers/Open linkView original on lemmy.world

UEFA Ticket app shares users' location data with police

To attend the championship this year, fans must use a digital ticket provided through UEFA’s Ticket application. According to Heise, this app requires access to personal data, including name, email, phone number, and GPS permissions. While app store descriptions note the collection of personal information and activity data for analysis purposes, they omit any mention of location sharing.

UEFA Ticket app shares users' location data with policehttps://stackdiary.com/uefa-ticket-app-shares-users-location-data-with-police/Open linkView original on lemmy.world

OpenAI seeks NYT source material for copyright defense

OpenAI, which is co-defendant with Microsoft, is seeking an informal discovery conference to compel the Times to produce documents demonstrating the originality and ownership of the copyrighted works in question. According to OpenAI’s court filing, the information is critical to their defense against claims of copyright infringement.

OpenAI seeks NYT source material for copyright defensehttps://stackdiary.com/openai-seeks-nyt-source-material-for-copyright-defense/Open linkView original on lemmy.world