Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    What Happens to the Stock Market When Baby Boomers Sell?

    June 19, 2026

    Vance Delays Trip To Switzerland To Lead New U.S. Talks With Iran On Its Nuclear Program

    June 19, 2026

    The Best Early Prime Deals on Fitness Equipment

    June 19, 2026
    Facebook X (Twitter) Instagram
    Trending
    • What Happens to the Stock Market When Baby Boomers Sell?
    • Vance Delays Trip To Switzerland To Lead New U.S. Talks With Iran On Its Nuclear Program
    • The Best Early Prime Deals on Fitness Equipment
    • Lightning Crotch Pregnancy Symptom You Should Know
    • Trump Administration Claims It Made The Reflecting Pool Blue. See For Yourself!
    • Liberal ‘View’ Host Told JD Vance He Had Good Vibe And Should Run For President
    • Rejected By Mom, Then Lost My Own Child In Prison
    • How to use your CRM for smarter email marketing campaigns
    Facebook X (Twitter)
    SBM Global News
    Demo
    • Home
    • Top Stories
      • Politics
    • Business
      • Small Business
      • Marketing
    • Finance
      • Investment
    • Technology

      How to turn off AI in your Google Docs

      June 18, 2026
      Read More

      Codelattice – Company Profile – AllBusiness.com

      June 17, 2026
      Read More

      DOJ claims xAI’s unpermitted gas turbines are a matter of ‘national, economic, and energy security’

      June 17, 2026
      Read More

      SpaceX’s Stock Surges on First Full Day of Trading

      June 16, 2026
      Read More

      New Town Spares – Company Profile

      June 15, 2026
      Read More
    • Lifestyle
      • Travel
    • Feel Good
    • Get In Touch
    SBM Global News
    Demo
    Home»Technology»US, Australia cyber agencies warn IDOR security flaws can be exploited ‘at scale’
    Technology

    US, Australia cyber agencies warn IDOR security flaws can be exploited ‘at scale’

    By Staff WriterJuly 28, 20233 Mins Read
    Facebook Twitter LinkedIn Reddit Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    U.S. and Australian government cybersecurity agencies are warning that common and easily exploitable security vulnerabilities in websites and web apps can be abused to carry out large-scale data breaches.

    In a joint advisory published Thursday, U.S. cybersecurity agency CISA, the National Security Agency and the Australian Cyber Security Centre said that the vulnerabilities, known as insecure direct object references (IDORs), allow malicious hackers to access or modify sensitive data on an organization’s servers because of a lack of proper security checks.

    An IDOR vulnerability is like having a key to your mailbox, but that key also allows you to unlock every other mailbox on your street. IDORs can be particularly problematic because, like a row of mailboxes, a bad actor can exploit them sequentially one after the other and access data that they should not be allowed to.

    Because these vulnerabilities can often be exploited by enumeration, IDORs can be abused “at scale” using automated tools, the advisory warns.

    “While there have been prior open source reports on insecure direct object reference (IDOR) vulnerabilities in web applications, CISA and our partners at the Australian Cyber Security Centre and National Security Agency realized this is a major flaw with too little recognition or understanding within the cyber community. Today’s joint advisory is the first significant advisory on this subject to help organizations protect sensitive data in their systems and push vendors to reduce prevalence of IDOR vulnerabilities and flaws,” James Stanley, CISA Product Development Section Chief, told TechCrunch.

    The joint advisory notes that IDORs have resulted in major data breaches in the United States and overseas.

    In recent years, IDORs have resulted in the exposure of thousands of medical documents by a U.S. laboratory giant, a state government website that spilled thousands of taxpayers’ personal information, a college contact-tracing app that leaked COVID-19 vaccination status and a state-backed health app that allowed access to other people’s vaccination data. IDORs also resulted in the mass data spill of hundreds of millions of U.S. mortgage documents, the exposure of the real-time location data of more than a million vehicles from a flawed GPS tracker and the leak of hundreds of thousands of people’s private phone data stolen by a global stalkerware network.

    The joint advisory says developers should ensure their web apps perform authentication and authorization checks to reduce IDORs, and that software is secure-by-design, a principle promoted by CISA that urges software makers to bake-in security from the beginning and throughout the software development process.

    “Secure-by-design is a fundamental theme in this advisory. Vendors and developers are encouraged to take appropriate steps to provide products that protect their customers’ sensitive data by design and default,” said CISA’s Stanley.

    Australia’s cyber agency said it continues to observe malicious actors exploiting misconfigured networks.

    “Even a single breach using IDOR vulnerabilities can have a national impact. A malicious actor being able to exfiltrate data could impact critical infrastructure, businesses, government and individuals,” said Patrick Holmes with the Australian Cyber Security Centre.

    Fake passports, real bank accounts: How TheTruthSpy stalkerware made its millions

    Originally published at techcrunch.com

    devices gadgets notebooks phones tablets technology
    Share. Facebook Twitter LinkedIn Email Reddit
    Previous ArticleReels, ads and cost cutting propel Meta’s stock to 17-month high. How the pros are playing it
    Next Article A new study found that Facebook’s Pages and Groups shape its ideological echo chambers

    Related Posts

    How to turn off AI in your Google Docs

    June 18, 2026
    Read More

    Codelattice – Company Profile – AllBusiness.com

    June 17, 2026
    Read More

    DOJ claims xAI’s unpermitted gas turbines are a matter of ‘national, economic, and energy security’

    June 17, 2026
    Read More
    Add A Comment

    Leave A Reply Cancel Reply

    Demo
    Top Posts

    Former FBI, CIA Head Has ‘Serious Concerns’ With Trump Cabinet Picks

    December 28, 2024435

    Emirates to operate next-gen A350 on the third daily service to Cape Town

    January 14, 2026256

    AAVE Price Prediction: Target $215-225 by Mid-January 2025 as Technical Indicators Signal Bullish Momentum

    December 15, 2025240

    Ventive Hospitality Joins Green Fins: Strong ESG Lift

    February 17, 2026211
    Don't Miss
    Investment

    What Happens to the Stock Market When Baby Boomers Sell?

    By Staff WriterJune 19, 20265 Mins Read

    A reader asks: The “Relentless Bid” of 401ks has inflated stock prices and dampened volatility…

    Read More

    Vance Delays Trip To Switzerland To Lead New U.S. Talks With Iran On Its Nuclear Program

    June 19, 2026

    The Best Early Prime Deals on Fitness Equipment

    June 19, 2026

    Lightning Crotch Pregnancy Symptom You Should Know

    June 19, 2026
    Stay In Touch
    • Facebook
    • Twitter
    Demo
    About Us

    Small Business Minder brings together business and related news from around the world in one place. Follow us for all the business news you'll need.

    Facebook X (Twitter)
    Our Picks

    What Happens to the Stock Market When Baby Boomers Sell?

    June 19, 2026

    Vance Delays Trip To Switzerland To Lead New U.S. Talks With Iran On Its Nuclear Program

    June 19, 2026
    Most Popular

    Former FBI, CIA Head Has ‘Serious Concerns’ With Trump Cabinet Picks

    December 28, 2024435

    Emirates to operate next-gen A350 on the third daily service to Cape Town

    January 14, 2026256
    © 2026 Small Business Minder
    • Home
    • Get In Touch

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. To get the most from our site, please disable your Ad Blocker.