Showing only posts by Thomas Claburn. Show all posts.

Don't be like these 900+ websites and expose millions of passwords via Firebase

Source

Warning: Poorly configured Google Cloud databases spill billing info, plaintext credentials At least 900 websites built with Google's Firebase, a cloud database, have been misconfigured, leaving credentials, personal info, and other sensitive data inadvertently exposed to the public internet, according to security researchers.... [...]

Insurance website's buggy API leaked Office 365 password and a giant email trove

Source

Pen-tester accessed more than 650,000 sensitive messages, and still can, at Indian outfit using Toyota SaaS Toyota Tsusho Insurance Broker India (TTIBI), an Indo-Japanese joint insurance venture, operated a misconfigured server that exposed more than 650,000 Microsoft-hosted email messages to customers, a security researcher has found.... [...]

« newer articles | page 4 | older articles »