任意のGoogleユーザーの電話番号を漏洩させる
IPv6の膨大なアドレス空間と巧妙なBotGuard回避により、レート制限が無効化され、すべてのGoogleユーザーの電話番号が脆弱な状態に置かれました。このセキュリティ問題は、Googleの認証システムにおける重大な欠陥を明らかにしています。
IPv6の膨大なアドレス空間と巧妙なBotGuard回避により、レート制限が無効化され、すべてのGoogleユーザーの電話番号が脆弱な状態に置かれました。このセキュリティ問題は、Googleの認証システムにおける重大な欠陥を明らかにしています。
DDoSecrets has released 410 GB of heap dump data obtained from a hack of TeleMessage's archive server. The data includes information from the company's customers, which reportedly include law enforcement agencies and financial institutions.
TeleMessage's customer list includes DC Police, Andreessen Horowitz, JP Morgan, and hundreds of other organizations, according to analysis of 410 GB of Java heap dumps from the company's archive server.
A security researcher discovered that BrowserStack is leaking users' email addresses. The researcher uses unique email addresses for each service and identified BrowserStack as the source of email leaks. This allows tracking which services are responsible for data exposure.
Micah Lee has created an open source research tool called TeleMessage Explorer to analyze data from a massive hack of TeleMessage, the company behind a modified Signal app used by Trump's former national security advisor Mike Waltz.
Apollo.io claims to have obtained the author's phone number from Parsely, Inc (wpvip.com), which participates in Apollo's customer contributor network by sharing data. The author questions whether WordPress VIP leaked their personal information.