A logo of US company Microsoft is displayed during the Vivatech technology startups and innovation fair, at the Porte de Versailles exhibition center in Paris, on May 22, 2024. (Photo by JULIEN DE ROSA / AFP / Getty Images) Here’s how misconfigurations in Microsoft Power Pages could lead to data breaches AppOmni researchers found that a misunderstanding of access controls can lead to PII being taken from these low-code websites. Nov 14, 2024 By Greg Otto
Walgreens discovered the flaw on Jan. 15 and promptly disabled the feature before fixing the app. (Getty Images) Walgreens app exposes customer prescription data An “error” in the Walgreens app left some customer data exposed for several days in January. Mar 2, 2020 By Sean Lyngaas
(Getty Images) Exclusive: PR software firm exposes data on nearly 500k contacts The company removed the bucket from the open internet after being contacted by CyberScoop. Dec 9, 2019 By Greg Otto
A Quest Diagnostics sign outside the New York Stock Exchange in November 2016. (Quest Diagnostics) Quest Diagnostics pins breach affecting 11.9 million patients on debt collector The unauthorized access occurred between August 1, 2018 and March 30, according to an SEC filing. Jun 3, 2019 By Jeff Stone
(iStock / Getty Images Plus) Chinese database exposes 42.5 million records compiled from multiple dating apps Most of the data was about American users. May 29, 2019 By Jeff Stone
(Isriya Paireepairit / Flickr) Third-party Facebook apps left people’s data publicly exposed, researchers say The Silicon Valley security firm identified exposures by Mexico-based media company Cultura Colectiva and the now-defunct "At the Pool" app. Apr 3, 2019 By Joe Warminsky
(Pixabay) Chinese e-commerce giant Gearbest leaks millions of records, researcher finds “Gearbest’s database isn’t just unsecured. It’s also providing potentially malicious agents with a constantly-updated supply of fresh data.” Mar 14, 2019 By Jeff Stone
(Pixabay) ‘Gold mine’ of customer loan, tax and other records exposed on open server 24 million records, one server, no password. Jan 23, 2019 By Zaid Shoorbajee
A screenshot of a Chinese classified web page, where users first input personal data that may have been leaked by a data collection firm (Bob Diachenko). Personal data on 202 million Chinese job-seekers left exposed on insecure database The database did not require visitors to enter a username or password to access the information. Jan 10, 2019 By Jeff Stone
Screenshot from Hacken’s report on exposed Elasticsearch servers. (Hacken) Data about 57 million people exposed by Elasticsearch servers Cybersecurity organization Hacken said it found the misconfigured servers as part of a regular security audit. The data appears to come from millions of U.S. residents. Nov 28, 2018 By Jared Beinart