LIVE · cybersecurity feed
Live wire
Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainHow an Emerging Industrial Protocol Family Could Put OT at Risk14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentials
breach

Reverse-Lookup Service Exposed Millions of Photos of People’s Faces

The people-search tool ClarityCheck says its reverse image search service is “private and secure”—but it left a database containing more than 9 million image files exposed.

zeroday.news ·

A reverse image search service called ClarityCheck, which claims to identify individuals from photos, exposed a database containing over 9 million image files, including photographs of faces. The exposed data, totaling approximately 450 GB, was stored in an unsecured Amazon S3 bucket, accessible online without authentication.

Independent security researcher Jeremiah Fowler discovered the exposure, noting that the files were organized in folders labeled "faces" and "profiles." The images included profile pictures, screenshots, and other photographs of adults, teenagers, and children. Fowler also identified a separate misconfiguration that exposed users' email addresses and phone numbers through manipulated website URLs.

ClarityCheck is a "people-finder" tool that offers searches based on phone numbers, email addresses, vehicle identification numbers, and names. Its photo-search feature purports to identify individuals in photos and locate their social media profiles. The company's website states that its reverse image search is "private and secure."

Fowler reported the issue to ClarityCheck, but initially faced difficulties. The company secured the image database and the API misconfiguration after being contacted by a news outlet in July. ClarityCheck stated that it acted immediately to restrict access once the issues were brought to the attention of the appropriate teams.

However, ClarityCheck disputed the characterization of the data as "publicly exposed," arguing that access required knowledge of a specific, unindexed URL not discoverable through ordinary use or general web searches. The company also claimed that the data included duplicate, cropped, and resized copies, along with non-image data, rather than 9 million unique images.

Security experts generally define data as exposed if it can be accessed by unauthorized individuals on the open internet without authentication. This includes misconfigured storage buckets or publicly reachable database backups.

The exposed images, particularly facial data, are considered highly sensitive biometric information. While ClarityCheck's website requires users to confirm they have permission to upload photos, Fowler noted that individuals whose faces were in the database might have been unaware their images were collected, especially since the service is designed for identification. Such data could be used for AI training or by scammers.

The email addresses and phone numbers exposed through the API misconfiguration were described by ClarityCheck as being sourced from publicly available information and licensed third-party data providers.

ClarityCheck has stated that it has improved its security reporting procedures to facilitate future communication with researchers. The incident highlights the risks associated with platforms that collect and analyze sensitive personal data, even with accidental misconfigurations.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Welcoming the Sri Lankan Government to Have I Been Pwned

Today, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri Lanka. Sri Lanka CERT now has access to monitor Sri Lankan government domains against the data in HIBP, helping identify exposed government accounts and respond when they appear in new data breaches.

malware

ToxicPanda Android malware uses VPN permissions to block Google Play

The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]

iran

UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks

Hackers linked to Iran have successfully disabled a small UK power plant for four days, marking the first confirmed attack of its kind against the nation's energy infrastructure. The incident occurred concurrently with cyberattacks targeting water facilities across 12 US states. While the UK power plant's outage did not impact the national grid, the attack served as a demonstration of capability, with intentions likely focused on showcasing access rather than causing widespread disruption.

ransomware

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows 11’s strongest security defenses can be bypassed without a screwdriver Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assume

aihigh

Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context Injection

Researchers at Adversa AI have developed a novel attack called Cryptographic Context Injection, which bypasses AI safety filters by embedding malicious instructions within AES-encrypted payloads. This technique tricks AI models like xAI's Grok and Google's Gemini into decrypting and executing these hidden commands. In the case of Grok, the attack can lead to zero-click theft of user chat histories and personal data by disguising the malicious payload as a webpage summary request.

security

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

The rules have already been rejected by multiple state courts, but the Trump administration said it’s preparing in case of a favorable Supreme Court decision. The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.