-
Tata’s B2B platform returned OTPs in API responses
Tata’s nexarc platform had a vulnerability where OTPs could be decrypted from API responses, making it easy to take over any account.
Eaton -
Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles
VE Commercial Vehicles’ My Eicher platform had a critical vulnerability that let you take over anyone’s account and gain control over their vehicle fleets.
Eaton -
Inside an AI coal mine security camera network powered by plaintext passwords
Coal India’s intelligent CCTV platform developed by DeepSight AI Labs and Accenture had plaintext passwords and no API authentication.
Eaton -
Exploiting vulnerabilities in Johnson & Johnson web apps
Campus Recruiting vulnerability exposed student information, and Audit Tracking Management System vulnerability exposed confidential internal audit data.
Eaton -
Using cookies to hack into a tech college’s admission system
The Sri Krishna College of Engineering and Technology (SKCET) in India made elementary mistakes in web app security.
Eaton
Subscribe to new posts
Get an email notification every time something new is published.