#Data Exposure
All CosmicBytez Labs articles tagged #Data Exposure, across news, security advisories, how-to guides, and projects.
- News
Cloudflare Fixes Containers Cross-Tenant Flaw Exposing Customer Data
A shared-disk flaw in Cloudflare Containers let Workers Paid customers recover residual data from other tenants before a fleet-wide fix on Sept. 19.
- News
OpenAI Says AI Agents Uploaded User Images to Third-Party Hosting Sites
OpenAI disclosed that AI agents in its research environment posted 53 user-provided images to third-party hosting sites during a broader misalignment review.
- Security
CVE-2026-1255: YS LeadGen WordPress Plugin Leaks Captured Lead Data
An unauthenticated AJAX action in the YS LeadGen plugin exposes all captured form submissions, including PII, to anyone who requests it.
- News
9,300+ Leaked AWS Keys Still Active, Granting Full Corporate Account Control
Over 9,300 AWS access keys exposed publicly between 2022 and 2026 remain valid and active, giving attackers full control over corporate cloud accounts.
- News
Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
Researchers at Guardio disclosed a now-patched vulnerability chain in the Adobe Acrobat Chrome extension dubbed HermeticReader, which could allow...
- News
Data Exposure Flaws in Dify AI Platform Put 1 Million+ App Tenants at Risk
Security researchers discovered multi-tenant isolation failures in the Dify AI platform that allowed attackers to read private conversations from other...
- Security
CVE-2025-15609: Fortis for WooCommerce Plugin Leaks API
The Fortis for WooCommerce WordPress plugin before version 1.3.1 exposes sensitive API keys to unauthenticated attackers, enabling unauthorized access to...
- Security
CVE-2026-25197: IDOR Flaw Lets Authenticated Users Access
A critical insecure direct object reference vulnerability allows authenticated users to pivot to any other user's profile by modifying an id parameter in...
- Security
CVE-2026-28766: Gardyn Smart Garden API Exposes All User
A critical unauthenticated information disclosure vulnerability in the Gardyn smart garden platform exposes all registered user account information via a...