McDonald's not lovin' it when hacker exposes rotten security
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A white-hat hacker discovered multiple critical security vulnerabilities in McDonald's systems, including client-side only validation allowing free food orders, exposed API keys in JavaScript, faulty OAuth implementation giving unauthorized access to executive portals, and missing admin authorization on franchise portals. The company took months to fix issues and fired an employee who helped with the research. Additional vulnerabilities were found in the AI chatbot used for job applications, which had a password of 123456 and exposed 64 million applicant records.
Table of contents
It's not just staff getting a serving of poor securityOh my god, they killed privacy1 Comment
Sort: