McDonald’s AI bot spills data on job applicants
ID: 493de499-261c-5e1b-b7d6-f9dc8b1489cf
STIX ID: report--493de499-261c-5e1b-b7d6-f9dc8b1489cf
Feed Name: Malwarebytes Blog
Threat Score
Researchers found that McDonald’s McHire hiring chatbot and backend accepted default credentials (e.g., 123456:123456) and exposed an API that allowed access to virtually every application submitted to McDonald’s over years—potentially impacting up to tens of millions of applicants; Paradox.ai/McDonald’s patched the vulnerability after disclosure and there are no indications of prior criminal exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
