• About
  • Disclaimer
  • Privacy Policy
  • Contact
Saturday, July 19, 2025
Cyber Defense GO
  • Login
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration
No Result
View All Result
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration
No Result
View All Result
Cyber Defense Go
No Result
View All Result
Home Cyber Security

McDonald’s AI hiring software’s password ‘123456’ uncovered knowledge of 64M candidates

Md Sazzad Hossain by Md Sazzad Hossain
0
McDonald’s AI hiring software’s password ‘123456’ uncovered knowledge of 64M candidates
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter

You might also like

Risk actors scanning for apps incorporating weak Spring Boot software

Poor Passwords Tattle on AI Hiring Bot Maker Paradox.ai – Krebs on Safety

Choo Choo Select to disregard the vulnerability • Graham Cluley



“Though the app tries to pressure single sign-on (SSO) for McDonald’s, there’s a smaller hyperlink for ‘Paradox group members’ that caught our eye,” Carroll stated. “With out a lot thought, we entered ‘123456’ because the password and have been stunned to see we have been instantly logged in!”

As soon as inside, researchers moreover found an inner API endpoint utilizing a predictable parameter to fetch applicant knowledge. By merely decrementing the ID worth, Caroll and Curry retrieved full applicant PII, together with chat transcripts, contact data, and job-form knowledge. This IDOR exploit uncovered not simply contact particulars but additionally timestamps, shift preferences, persona take a look at outcomes, and even tokens that might impersonate candidates on McHire.

“This incident is a primary instance of what occurs when organizations deploy expertise with out an understanding of the way it works or how it may be operated by untrusted customers,” Desired Impact CEO Evan Dornbush stated. “With AI techniques dealing with thousands and thousands of delicate knowledge factors, organizations should put money into understanding and mitigating pre-emergent threats, or they’ll discover themselves taking part in catch-up, with their prospects’ belief on the road.”

Tags: 64MapplicantsDataexposedHiringMcDonaldsPasswordTools
Previous Post

Deploy Airflow to AWS ECS – Dataquest

Next Post

On the subject of broadband for everybody, CommScope is all in on BABA

Md Sazzad Hossain

Md Sazzad Hossain

Related Posts

Risk actors scanning for apps incorporating weak Spring Boot software
Cyber Security

Risk actors scanning for apps incorporating weak Spring Boot software

by Md Sazzad Hossain
July 19, 2025
Poor Passwords Tattle on AI Hiring Bot Maker Paradox.ai – Krebs on Safety
Cyber Security

Poor Passwords Tattle on AI Hiring Bot Maker Paradox.ai – Krebs on Safety

by Md Sazzad Hossain
July 18, 2025
Cyber Security

Choo Choo Select to disregard the vulnerability • Graham Cluley

by Md Sazzad Hossain
July 18, 2025
Hackers Use GitHub Repositories to Host Amadey Malware and Knowledge Stealers, Bypassing Filters
Cyber Security

Hackers Use GitHub Repositories to Host Amadey Malware and Knowledge Stealers, Bypassing Filters

by Md Sazzad Hossain
July 17, 2025
The Carruth Knowledge Breach: What Oregon Faculty Staff Must Know
Cyber Security

Why Your Wi-Fi Works however Your Web Doesn’t (and How you can Repair It)

by Md Sazzad Hossain
July 17, 2025
Next Post
On the subject of broadband for everybody, CommScope is all in on BABA

On the subject of broadband for everybody, CommScope is all in on BABA

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Kinesiska MiniMax lanserar öppna källkodsmodeller

Kinesiska MiniMax lanserar öppna källkodsmodeller

January 17, 2025
No, Brad Pitt is not in love with you

No, Brad Pitt is not in love with you

January 17, 2025

Categories

  • Artificial Intelligence
  • Computer Networking
  • Cyber Security
  • Data Analysis
  • Disaster Restoration
  • Machine Learning

CyberDefenseGo

Welcome to CyberDefenseGo. We are a passionate team of technology enthusiasts, cybersecurity experts, and AI innovators dedicated to delivering high-quality, insightful content that helps individuals and organizations stay ahead of the ever-evolving digital landscape.

Recent

Intro to Docker Compose – Dataquest

Intro to Docker Compose – Dataquest

July 19, 2025
The Definitive Information to AI Brokers: Architectures, Frameworks, and Actual-World Purposes (2025)

The Definitive Information to AI Brokers: Architectures, Frameworks, and Actual-World Purposes (2025)

July 19, 2025

Search

No Result
View All Result

© 2025 CyberDefenseGo - All Rights Reserved

No Result
View All Result
  • Home
  • Cyber Security
  • Artificial Intelligence
  • Machine Learning
  • Data Analysis
  • Computer Networking
  • Disaster Restoration

© 2025 CyberDefenseGo - All Rights Reserved

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In