Emerging Indian social media app Slick left an internal database containing users’ personal information, including data of school-going children, publicly exposed to the internet for months.
Since at least December 11, a database containing full names, mobile numbers, dates of birth, and profile pictures of Slick users was left online without a password.
Bengaluru-based Slick launched in November 2022 by former Unacademy executive Archit Nanda after pivoting from crypto and closing his earlier startup CoinMint. His latest venture, Slick, is available on both Android and iOS and works similarly to Gas, a compliments-based app that is popular in the United States. The app also allows school and college students to talk with and about their friends anonymously.
Security researcher Anurag Sen from CloudDefense.ai found the exposed database, and asked TechCrunch for help in reporting the incident to the social media startup. Slick secured the database a short time after TechCrunch reached out on Friday.
Due to a misconfiguration, anyone familiar with the database’s IP address could access the database, which contained entries of over 153,000 users at the time it was secured. TechCrunch also found that the database could be accessed by an easy-to-guess subdomain on Slick’s main website.
The researcher also informed the India’s computer emergency response team, known as CERT-In, the country’s lead agency for handling cybersecurity issues.
Nanda confirmed to TechCrunch that Slick fixed the exposure. It’s not known if anyone other than Sen found the database before it was secured.
Slick attracted many younger users in India shortly after debuting last year. Earlier this month, Nanda took to Twitter to announce that the app crossed 100,000 downloads.
The U.S. government’s cybersecurity agency has warned that criminal financially motivated hackers compromised federal agencies using legitimate remote desktop software. CISA said in a joint advisory with the National Security Agency on Wednesday that it had identified a “widespread cyber campaign involving the malicious use of legitimate remote monitoring and management (RMM) software” that had targeted multiple […]
Cybercriminals are actively exploiting a two-year-old VMware vulnerability as part of a ransomware campaign targeting thousands of organizations worldwide. Reports emerged over the weekend that VMware ESXi servers left vulnerable and unpatched against a remotely exploitable bug from 2021 were compromised and scrambled by a ransomware variant dubbed “ESXiArgs.” ESXi is VMware’s hypervisor, a technology that […]
Australian software giant Atlassian and Envoy, a startup that provides workplace management services, were at loggerheads on Thursday over a data breach that exposed the data of thousands of Atlassian employees. As first reported by Cyberscoop, a hacking group known as SiegedSec leaked data on Telegram this week that it claimed to have stolen from Atlassian. This […]
Leave a Reply