The ChatGPT Redis Bug: Cross-Tenant Leaks in One Line
A redis-py cancellation bug plus a disabled key-prefix let some ChatGPT users see strangers' chat titles and billing data. Multi-tenant cache lessons.
A redis-py cancellation bug plus a disabled key-prefix let some ChatGPT users see strangers' chat titles and billing data. Multi-tenant cache lessons.
Researchers pulled Bing Chat's hidden rules with polite overrides, revealing the codename Sydney and confidential guidelines. Prompt-injection's big bang.
Phishers compromised a SendGrid supplier account and sent MetaMask-themed mail through Namecheap's legitimate pipeline — SPF, DKIM, and DMARC all passed.
A cloned intranet page harvested an employee's password and MFA code, opening hours of internal access. Phishing-resistant MFA and self-report lessons.
GoDaddy's 2023 filing admitted intermittent intruder access since 2020, malware in cPanel servers, and email interception affecting ~6.95M customers.
ESXiArgs hit thousands of unpatched VMware ESXi hosts via old OpenSLP bugs in February 2023. Hypervisor ransomware and recovery-script lessons.
Git's January 2023 advisory flagged plaintext credential stores and verbose logs echoing 2FA tokens. Developer tooling is production security surface.
A single compromised API credential let an actor scrape ~37 million T-Mobile accounts over six weeks. Machine-identity governance lessons from a repeat offender.
LockBit encrypted Royal Mail's international sorting operations in January 2023 and demanded $80M. Royal Mail paid nothing and kept the letters moving.
CVE-2023-24055 showed a config-planted trigger could export KeePass vaults in plaintext after unlock. The debate: feature, flaw, or threat model?
LastPass confirmed attackers copied encrypted vault backups after pivoting through a DevOps engineer's endpoint. KDF legacy and unencrypted metadata set the real risk.
Ransomware forced the Guardian's newsroom off its networks for weeks in late 2022 — yet print and web kept publishing. Editorial continuity lessons.