Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The Easy Summer Weekend Outfit · Primer

    May 18, 2026

    What Does It Mean If You Get Winded From Walking Up Stairs?

    May 18, 2026

    How to do keyword research for AEO (+ Tools)

    May 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Easy Summer Weekend Outfit · Primer
    • What Does It Mean If You Get Winded From Walking Up Stairs?
    • How to do keyword research for AEO (+ Tools)
    • Apple’s Siri revamp could include auto-deleting chats
    • Kerten Hospitality sees a strong opportunity and will target 1,000 Keys in India
    • Is This a Bubble? – A Wealth of Common Sense
    • Democratic Senator Argues Kash Patel Has ‘Weaponized The FBI’
    • Trump Blasts ‘Disloyal’ GOP Senator Who Voted To Impeach Him
    Facebook X (Twitter)
    SBM Global News
    Demo
    • Home
    • Top Stories
      • Politics
    • Business
      • Small Business
      • Marketing
    • Finance
      • Investment
    • Technology

      Apple’s Siri revamp could include auto-deleting chats

      May 18, 2026
      Read More

      Website Developers India – Company Profile

      May 18, 2026
      Read More

      The haves and have nots of the AI gold rush

      May 17, 2026
      Read More

      Kernel Tech – Company Profile

      May 16, 2026
      Read More

      What the jury will actually decide in the case of Elon Musk vs. Sam Altman

      May 15, 2026
      Read More
    • Lifestyle
      • Travel
    • Feel Good
    • Get In Touch
    SBM Global News
    Demo
    Home»Technology»US, Australia cyber agencies warn IDOR security flaws can be exploited ‘at scale’
    Technology

    US, Australia cyber agencies warn IDOR security flaws can be exploited ‘at scale’

    By Staff WriterJuly 28, 20233 Mins Read
    Facebook Twitter LinkedIn Reddit Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    U.S. and Australian government cybersecurity agencies are warning that common and easily exploitable security vulnerabilities in websites and web apps can be abused to carry out large-scale data breaches.

    In a joint advisory published Thursday, U.S. cybersecurity agency CISA, the National Security Agency and the Australian Cyber Security Centre said that the vulnerabilities, known as insecure direct object references (IDORs), allow malicious hackers to access or modify sensitive data on an organization’s servers because of a lack of proper security checks.

    An IDOR vulnerability is like having a key to your mailbox, but that key also allows you to unlock every other mailbox on your street. IDORs can be particularly problematic because, like a row of mailboxes, a bad actor can exploit them sequentially one after the other and access data that they should not be allowed to.

    Because these vulnerabilities can often be exploited by enumeration, IDORs can be abused “at scale” using automated tools, the advisory warns.

    “While there have been prior open source reports on insecure direct object reference (IDOR) vulnerabilities in web applications, CISA and our partners at the Australian Cyber Security Centre and National Security Agency realized this is a major flaw with too little recognition or understanding within the cyber community. Today’s joint advisory is the first significant advisory on this subject to help organizations protect sensitive data in their systems and push vendors to reduce prevalence of IDOR vulnerabilities and flaws,” James Stanley, CISA Product Development Section Chief, told TechCrunch.

    The joint advisory notes that IDORs have resulted in major data breaches in the United States and overseas.

    In recent years, IDORs have resulted in the exposure of thousands of medical documents by a U.S. laboratory giant, a state government website that spilled thousands of taxpayers’ personal information, a college contact-tracing app that leaked COVID-19 vaccination status and a state-backed health app that allowed access to other people’s vaccination data. IDORs also resulted in the mass data spill of hundreds of millions of U.S. mortgage documents, the exposure of the real-time location data of more than a million vehicles from a flawed GPS tracker and the leak of hundreds of thousands of people’s private phone data stolen by a global stalkerware network.

    The joint advisory says developers should ensure their web apps perform authentication and authorization checks to reduce IDORs, and that software is secure-by-design, a principle promoted by CISA that urges software makers to bake-in security from the beginning and throughout the software development process.

    “Secure-by-design is a fundamental theme in this advisory. Vendors and developers are encouraged to take appropriate steps to provide products that protect their customers’ sensitive data by design and default,” said CISA’s Stanley.

    Australia’s cyber agency said it continues to observe malicious actors exploiting misconfigured networks.

    “Even a single breach using IDOR vulnerabilities can have a national impact. A malicious actor being able to exfiltrate data could impact critical infrastructure, businesses, government and individuals,” said Patrick Holmes with the Australian Cyber Security Centre.

    Fake passports, real bank accounts: How TheTruthSpy stalkerware made its millions

    Originally published at techcrunch.com

    devices gadgets notebooks phones tablets technology
    Share. Facebook Twitter LinkedIn Email Reddit
    Previous ArticleReels, ads and cost cutting propel Meta’s stock to 17-month high. How the pros are playing it
    Next Article A new study found that Facebook’s Pages and Groups shape its ideological echo chambers

    Related Posts

    Apple’s Siri revamp could include auto-deleting chats

    May 18, 2026
    Read More

    Website Developers India – Company Profile

    May 18, 2026
    Read More

    The haves and have nots of the AI gold rush

    May 17, 2026
    Read More
    Add A Comment

    Leave A Reply Cancel Reply

    Demo
    Top Posts

    Former FBI, CIA Head Has ‘Serious Concerns’ With Trump Cabinet Picks

    December 28, 2024435

    Emirates to operate next-gen A350 on the third daily service to Cape Town

    January 14, 2026256

    AAVE Price Prediction: Target $215-225 by Mid-January 2025 as Technical Indicators Signal Bullish Momentum

    December 15, 2025240

    Ventive Hospitality Joins Green Fins: Strong ESG Lift

    February 17, 2026211
    Don't Miss
    Lifestyle

    The Easy Summer Weekend Outfit · Primer

    By Staff WriterMay 18, 20262 Mins Read

    Shown here at two price points, a summer outfit that uses layers and pants and…

    Read More

    What Does It Mean If You Get Winded From Walking Up Stairs?

    May 18, 2026

    How to do keyword research for AEO (+ Tools)

    May 18, 2026

    Apple’s Siri revamp could include auto-deleting chats

    May 18, 2026
    Stay In Touch
    • Facebook
    • Twitter
    Demo
    About Us

    Small Business Minder brings together business and related news from around the world in one place. Follow us for all the business news you'll need.

    Facebook X (Twitter)
    Our Picks

    The Easy Summer Weekend Outfit · Primer

    May 18, 2026

    What Does It Mean If You Get Winded From Walking Up Stairs?

    May 18, 2026
    Most Popular

    Former FBI, CIA Head Has ‘Serious Concerns’ With Trump Cabinet Picks

    December 28, 2024435

    Emirates to operate next-gen A350 on the third daily service to Cape Town

    January 14, 2026256
    © 2026 Small Business Minder
    • Home
    • Get In Touch

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. To get the most from our site, please disable your Ad Blocker.