The Lab · 2026-03-25 18:27:32 · GitHub Issues
A critical security vulnerability has been discovered in a game server's API, exposing the complete historical dataset of player votes, scores, and session identifiers to anyone on the internet. The `/api/export/votes.csv` endpoint lacks any form of authentication, allowing uncredentialed access to download the entire ...
The Lab · 2026-04-14 20:22:56 · Hacker News
Fiverr, the gig work platform, has left sensitive customer files—including tax documents with personal identifiable information (PII)—publicly accessible and searchable on Google. The exposure stems from the company's use of Cloudinary, a service that processes PDFs and images shared between workers and clients. Instea...
The Lab · 2026-05-09 18:01:45 · Mastodon:hachyderm.io:#privacy
A man wearing smart glasses secretly recorded a woman and then demanded payment to delete the footage from his social media accounts, exposing a disturbing escalation in how consumer wearable technology can be weaponized for exploitation. The incident transforms smart glasses from a passive privacy concern into an acti...