LIVE · cybersecurity feed
Live wire
CISA orders feds to patch Citrix NetScaler RCE flaw by SaturdayUS Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure AttacksCritical Avada WordPress theme flaw enables zero-click RCECVE-2026-15409 · Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterAnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodesCVE-2026-60004 · Hackers now exploit critical Gitea flaw in code injection attacksEmployee benefits platform Paylogix says hackers stole financial and health dataU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesCVE-2026-61979 · Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as VulnerableCVE-2024-28224 · A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
breach

AI girlfriend review site's secrets were exposed to the world for three weeks

Even testing and staging sites need protection from prying eyes

zeroday.news ·

Intimeros, a website specializing in reviews and evaluations of AI companion services, inadvertently exposed confidential editorial content for a period of three weeks due to an unsecured test site. The exposure included unpublished reviews, pricing information, and private product notes related to various AI boyfriend, girlfriend, and other companion services.

The incident occurred during a site redesign when a colleague of Mia Morin, Editor and AI Quality Analyst at Intimeros, disabled password protection on a test version of the website to share progress with a client. This protection was not reinstated, leaving the site publicly accessible for three weeks.

The vulnerability was discovered when Morin noticed that the test site had been indexed by Google. This indicated that a robots.txt file, which would typically prevent search engines from indexing development or staging environments, had not been implemented for the beta domain.

Further investigation revealed that the test site was directly connected to a live production database. While Intimeros confirmed that no user data was compromised, the exposed information represented a significant risk to the company's competitive intelligence. Competitors could have accessed Intimeros's entire editorial strategy and upcoming content.

Upon discovering the exposure, Morin and her team took immediate corrective actions. They restored password protection, implemented measures to block search engines from indexing the draft pages, and updated all system access keys. Intimeros has since adopted a policy to secure all test sites with the same rigor as their official website and now conducts weekly automated scans to identify any inadvertently exposed pages.

The incident highlights the critical importance of securing development and staging environments. Experts recommend ensuring that such sites are not only password-protected but also employ mechanisms to block search engine and AI crawling. For enhanced security, placing staging sites on private servers and requiring VPN access are also advised.

breachai
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

OpenAI: Hugging Face Incident a “Warning Shot” to the World

OpenAI reveals that unauthorized message boards were at the heart of the recent Hugging Face breach

vulnerability

White House bans foreign-made equipment for power generation over cyber backdoor concerns

The Trump administration is banning the acquisition of foreign-made components used to manage electricity and power, alleging that “certain foreign actors are increasingly creating and exploiting vulnerabilities” in the technology.

security

Chinese Routers Sold Worldwide Contain Backdoors

An untold numbers of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.

vulnerabilityhigh

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

CISA has ordered U.S. government agencies to patch their Citrix NetScaler appliances against an actively exploited remote code execution vulnerability by Saturday. [...]

securitycritical

US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks

The operation focused on a group named QTFY, which offers hacking services to the Chinese government and others. The post US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks appeared first on SecurityWeek.

nation-state

Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure

The order says any foreign-produced equipment deemed to pose national security risks can’t be purchased or installed. The post Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure appeared first on CyberScoop.