pii-exposure

4 articles
sort: new top best
clear filter
0 3/10

Swedish e-government platform source code was leaked by threat actor ByteToBreach after compromising CGI Sverige AB infrastructure through Jenkins compromise, Docker escape, and SSH pivoting. The leak includes full platform source code, staff databases, API signing systems, and separately-sold citizen PII databases and electronic signing documents.

ByteToBreach CGI Sverige AB CGI Group Viking Line Slavia Pojistovna Sweden E-Gov Platform
darkwebinformer.com · tavro · 10 hours ago · details · hn
0 3/10

Telus Digital suffered a breach exposing nearly 1 petabyte of data after ShinyHunters obtained Google Cloud Platform credentials from a prior Salesloft-Drift breach and used trufflehog to exfiltrate customer support data, call records, source code, and financial information across 28+ impacted clients. The threat actors demanded $65M in extortion.

Telus Digital Telus ShinyHunters Salesloft Drift Google Cloud Platform BleepingComputer trufflehog Salesforce
mobilesyrup.com · whynotmaybe · 19 hours ago · details · hn
0 2/10

A researcher discovered an information disclosure vulnerability on a Google-acquired property by identifying an API endpoint that exposed user PII (personally identifiable information) when usernames were changed in the request URL, allowing enumeration of other users' private data.

Google Manas Harsh
infosecwriteups.com · kh4sh3i/bug-bounty-writeups · 20 hours ago · details
0 5/10

A bug bounty hunter discovered an information disclosure vulnerability in an enrollment portal where sensitive PII (last 4 SSN digits, account numbers, and verification answers) was exposed through missing rate limiting and HTML comments in the page source code, allowing account verification bypass.

Spazzy
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details