Oops. Ryan Fahey reports: The Cabinet Office uploaded the home and work addresses of more than 1,000 recipients of New Years’ Honours, including Elton John, Ben Stokes, Iain Duncan Smith and TV chef Nadiya Hussain. The work and home addresses of counter-terrorism officials, senior police and Ministry of Defence (MoD) staff were also included in…
Category: Exposure
IoT provider Wyze confirms server leak
Suzanne Larosa reports: Wyze, a company that sells smart devices such as security cameras, smart plugs, smart light bulbs and smart door locks, today confirmed a server leak that exposed the details of approximately 2.4 million customers. The leak occurred after an internal database was accidentally exposed online, Wyze co-founder Dongsheng Song said in a…
Vistaprint Logomaker files viewable due to insecure Amazon s3 bucket
Vistaprint. Everyone knows it and probably almost everyone knows somebody who has used the firm to design or print business cards, brochures, or other business-related stationery or marketing-related materials. Recently I was on Vistaprint’s site to create a new logo for ctrlbox.com. To my unpleasant surprise, I discovered that the preview of my logo displayed…
Philadelphia hepatitis data exposure posed ‘no risk to confidentiality’ because of Inquirer notification, city says
Nathaniel Lash reports: The medical records of thousands of Philadelphians were not compromised, the city said, after The Inquirer notified the city’s Health Department of a data breach that attached positive hepatitis test results with intimate personal details. This finding comes after an investigation by the city’s Public Health Department and a team with the…
Healthcare startup Lyfebin exposed medical images; startup denies they were real or identifiable patient data
Zack Whittaker reports: Healthcare startup Lyfebin exposed thousands of medical imaging files, such as X-rays, MRI scans and ultrasounds. The Los Angeles-based healthcare startup allows doctors and medical staff to store medical images in its “secure environment,” per its website, allowing patients and doctors access from anywhere. This seems to be one of those situations…
Fashion rental company HURR Collective exposed user information through misconfigured plugin
James Walker reports: HURR Collective, a UK-based fashion rental company, has notified around 400 users of a data security incident that resulted in their email addresses being exposed, The Daily Swig has learned. A misconfigured plugin on the HURR website meant that users’ email addresses could be obtained simply by clicking ‘View Source’ on certain web pages….