Fiverr Allegedly Leaks User Information to Google Indexing, Researchers Say
ID: 77c5ff0d-1890-55ff-8ad4-004986e7df56
STIX ID: report--77c5ff0d-1890-55ff-8ad4-004986e7df56
Feed Name: cybersecurityNews.com
Fiverr inadvertently exposed sensitive customer files (including completed tax forms) after misconfiguring its Cloudinary file-hosting integration to generate public, indexable URLs; Google indexed these files and a researcher, after an unacknowledged 40-day responsible disclosure, published the findings on Hacker News. The report warns of identity theft and regulatory implications and recommends immediate steps: halt sensitive file transfers, implement signed/time-limited URLs, request search de-indexing, and monitor for fraud.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
