Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Salt Storm APT Targets World Telecom and Vitality Sectors, Says Darktrace

    October 22, 2025

    Lenovo Coupon Codes and Offers: $5,000 Off

    October 22, 2025

    3 Should Hear Podcast Episodes For Addressing Worry, Failure, and Vulnerability In The Office

    October 22, 2025
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Home»AI Ethics & Regulation»McDonald’s AI hiring device’s password ‘123456’ uncovered information of 64M candidates
    AI Ethics & Regulation

    McDonald’s AI hiring device’s password ‘123456’ uncovered information of 64M candidates

    Declan MurphyBy Declan MurphyJuly 12, 2025No Comments1 Min Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    McDonald’s AI hiring device’s password ‘123456’ uncovered information of 64M candidates
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link



    “Though the app tries to pressure single sign-on (SSO) for McDonald’s, there’s a smaller hyperlink for ‘Paradox workforce members’ that caught our eye,” Carroll mentioned. “With out a lot thought, we entered ‘123456’ because the password and have been stunned to see we have been instantly logged in!”

    As soon as inside, researchers moreover found an inside API endpoint utilizing a predictable parameter to fetch applicant information. By merely decrementing the ID worth, Caroll and Curry retrieved full applicant PII, together with chat transcripts, contact data, and job-form information. This IDOR exploit uncovered not simply contact particulars but additionally timestamps, shift preferences, persona take a look at outcomes, and even tokens that might impersonate candidates on McHire.

    “This incident is a chief instance of what occurs when organizations deploy know-how with out an understanding of the way it works or how it may be operated by untrusted customers,” Desired Impact CEO Evan Dornbush mentioned. “With AI programs dealing with thousands and thousands of delicate information factors, organizations should put money into understanding and mitigating pre-emergent threats, or they’ll discover themselves enjoying catch-up, with their prospects’ belief on the road.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    Salt Storm APT Targets World Telecom and Vitality Sectors, Says Darktrace

    October 22, 2025

    Meta Rolls Out New Instruments to Shield WhatsApp and Messenger Customers from Scams

    October 21, 2025

    Microsoft 365 Copilot Flaw Lets Hackers Steal Delicate Information through Oblique Immediate Injection

    October 21, 2025
    Top Posts

    Salt Storm APT Targets World Telecom and Vitality Sectors, Says Darktrace

    October 22, 2025

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025

    Midjourney V7: Quicker, smarter, extra reasonable

    April 18, 2025
    Don't Miss

    Salt Storm APT Targets World Telecom and Vitality Sectors, Says Darktrace

    By Declan MurphyOctober 22, 2025

    A gaggle of state-sponsored (APT) actors, often called Salt Storm, stays a major menace to…

    Lenovo Coupon Codes and Offers: $5,000 Off

    October 22, 2025

    3 Should Hear Podcast Episodes For Addressing Worry, Failure, and Vulnerability In The Office

    October 22, 2025

    The Java Developer’s Dilemma: Half 2 – O’Reilly

    October 22, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2025 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.