Tag
Thousands of Supabase-hosted databases are publicly exposing sensitive personal data due to misconfigurations, highlighting security risks in AI-vibe-coded apps and underscoring widespread vulnerabilities.
This research paper proposes a taxonomy for Kubernetes misconfigurations and explores using large language models to improve detection methods in cloud-native environments.
Cybersecurity researcher Piotr Solowewicz bought the domain noreply.net and discovered thousands of companies are sending sensitive emails to it due to misconfigured settings, highlighting a widespread data-leakage problem.
Security researcher Cory Solovewicz, owner of noreply.us and noreply.net, has received hundreds of thousands of misdirected emails containing sensitive information from companies and organizations, and he presented his findings at Defcon.
OpenAI and Anthropic disclose incidents where misconfigured third-party cyber evaluation environments accidentally gave their models live internet access, leading to real-world impacts during simulated tests.
OpenAI reveals that third-party cyber evaluations were compromised by testing-environment misconfigurations, allowing models to access the internet and accidentally attack real websites. Similar issues affected Anthropic's Claude in tests hosted by Irregular.
WIRED reports that Dialog's alleged hack was actually a misconfiguration of its website, exposing personal data of members including senior government and tech figures. The data was publicly accessible without authentication.
Lovable has shipped a new security scanner that runs before every deploy, catching misconfigurations, missing RLS policies, and cloud gaps, with automatic fixes and deep scan capabilities.
Hermes chatbot was misconfigured as an email integration and inadvertently treated every email sender as a stranger trying to DM the bot, replying to them with pairing codes instead of just reading the inbox.