logo

Poor Passwords Tattle on AI Hiring Bot Maker Paradox.ai

ID: 90f518d2-2188-5606-9ca7-437601d94e24

STIX ID: report--90f518d2-2188-5606-9ca7-437601d94e24

Feed Name: Krebs on Security

Threat Score
75/100

Date Published: 2025-07-18

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

Security researchers found that a weakly protected Paradox.ai test account (password "123456") allowed access to McDonald’s applicant chatbot data, and separate evidence shows a Paradox developer in Vietnam was infected with Nexus Stealer, which exfiltrated hundreds of passwords and authentication cookies — including credentials to SSO and Atlassian accounts — potentially exposing multiple customer environments and millions of applicant records. Paradox asserts limited exposure and that some passwords were stale, but stolen tokens and reused weak passwords indicate significant operational security failures and active credential compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.