A family tracking app was leaking real-time location data - TechCrunch
https://techcrunch.com/2019/03/23/family-tracking-location-leak/
was leaking the real-time locations of more than 238,000 users for weeks
Bjarteblogg Ymse
https://techcrunch.com/2019/03/23/family-tracking-location-leak/
was leaking the real-time locations of more than 238,000 users for weeks
employees built applications that logged unencrypted password data for Facebook users and stored it in plain text on internal company servers.
170,000 hours of incredibly sensitive calls were stored on an open web server without any encryption or authentication, leaving personal information completely exposed for anyone with a web browser.
https://www.theverge.com/2019/1/10/18177305/ring-employees-unencrypted-customer-video-amazon
Smart doorbell company Ring allowed employees to share unencrypted customer videos with each other
https://www.bbc.co.uk/news/world-asia-46698646
a computer at a South Korean resettlement centre was hacked
Analysts say there are some concerns that the leak could endanger the families of the defectors that still remain in North Korea.
https://techcrunch.com/2018/12/14/facebook-photo-bug/
The bug allowed apps users had approved to pull their timeline photos to also receive their Facebook Stories, Marketplace photos, and most worryingly, photos they’d uploaded to Facebook but never shared.
https://www.theverge.com/2018/12/10/18134541/google-plus-privacy-api-data-leak-developers
the new vulnerability impacted 52.5 million users, who could have had profile information like their name, email address, occupation, and age exposed […] even if their account was set to private.
contained a guest’s name, postal address, phone number, date of birth, gender, email address, passport number, […] arrival and departure information, reservation date […]
https://www.nytimes.com/2018/08/31/world/middleeast/hacking-united-arab-emirates-nso-group.html
leaked documents and emails that directly challenge the company’s repeated assertions that it is not responsible for any illegal surveillance conducted by the governments that buy its spyware.
A company that sells surveillance software to parents and employers
hashed passwords and logins, Facebook messages
https://www.nytimes.com/2018/08/01/technology/data-breaches.html
Don’t reuse passwords, rely on two-factor verification, install software only from trusted sources, question any alert that pops up on your screen and get a password manager.
https://www.nytimes.com/2018/07/20/business/suppliers-data-leak-automakers.html
… the inadvertent exposure of customers’ data illustrates a problem confounding businesses: Some of their biggest security risks come from their suppliers and contractors.
http://www.cbc.ca/news/technology/carepartners-data-breach-ransom-patients-medical-records-1.4749515
The attackers told CBC News in an encrypted message that they discovered vulnerable software on CarePartners’ network that had not been updated in two years
https://www.aftenposten.no/kultur/i/L0xOAV/8500-Schibsted-kunder-berort-av-datalekkasje
Brukere av Aftenposten og Bergens Tidende har fått informasjon lekket i et hackerangrep mot tredjepartsløsningen Typeform.
The Guardian har laget en fin oversikt:

via guardian.co.uk