Belgae Social
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Pro@programming.devM to Technology@programming.devEnglish ·
edit-2
14 days ago

McDonald’s AI Hiring Bot exposed 64 Million McDonald’s job applications to security researchers Who Tried the Password ‘123456’

ian.sh

external-link
message-square
5
link
fedilink
3
external-link

McDonald’s AI Hiring Bot exposed 64 Million McDonald’s job applications to security researchers Who Tried the Password ‘123456’

ian.sh

Pro@programming.devM to Technology@programming.devEnglish ·
edit-2
14 days ago
message-square
5
link
fedilink
Would you like an IDOR with that? Leaking 64 million McDonald’s job applications
ian.sh
external-link
When applying for a job at McDonald's, over 90% of franchises use "Olivia," an AI-powered chatbot. We discovered a vulnerability that could allow an attacker to access more than 64 million job applications. This data includes applicants' names, resumes, email addresses, phone numbers, and personality test results.
  • ulterno@programming.dev
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    9 days ago

    then links to the company’s security@whatever email

    It didn’t on 2nd June so I’d say that’s not the case.
    Web pages change.

Technology@programming.dev

Technology@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

Share interesting Technology news and links.

Rules:

  1. No paywalled sites at all.
  2. News articles has to be recent, not older than 2 weeks (14 days).
  3. No videos.
  4. Post only direct links.

To encourage more original sources and keep this space commercial free as much as I could, the following websites are Blacklisted:

  • Al Jazeera.
  • NBC.
  • CNBC.
  • Substack.
  • Tom’s Hardware.
  • ZDNet.
  • TechSpot.
  • Ars Technica.
  • Vox Media outlets, with exception for Axios(Due to being ad free.)
  • Engadget.
  • TechCrunch.
  • Gizmodo.
  • Futurism.
  • PCWorld.
  • ComputerWorld.
  • Mashable.

More sites will be added to the blacklist as needed.

Encouraged:

  • Archive links in the body of the post.
  • Linking to the direct source, instead of linking to an article talking about the source.
Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 537 users / day
  • 2.19K users / week
  • 2.5K users / month
  • 2.5K users / 6 months
  • 1 local subscriber
  • 269 subscribers
  • 178 Posts
  • 605 Comments
  • Modlog
  • mods:
  • Pro@programming.dev
  • BE: 0.19.12
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org