logo

US cargo tech company publicly exposed its shipping systems and customer data to the web

ID: 67ae2868-a624-505d-b9d4-42694574dd00

STIX ID: report--67ae2868-a624-505d-b9d4-42694574dd00

Feed Name: TechCrunch Security News

Threat Score
72/100

Date Published: 2026-01-14

Date Updated: 2026-04-23

Author: Zack Whittaker

...
...

Security researcher Eaton Zveare discovered five critical flaws in Bluspark Global’s Bluvoyix shipping platform — an unauthenticated API, API test functionality exposing commands, plaintext-stored user passwords, and the ability to create admin accounts — which together allowed retrieval of user and historical shipment data dating back to 2007; Bluspark has since remediated the issues and is planning a disclosure program, though the company says there is no indication of customer impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.