UK Visa Portal exposed thousands of applicants’ passports and selfies — then called the lawyers on us

The third-party website exposed passports, selfies, and the location data of applicants who submitted their documents as part of the U.K. visa application process. Instead of fixing the issue, the website sent attorneys.

Trump Mobile confirms it exposed customers’ personal data, including phone numbers and home addresses

President Trump’s branded cell phone maker and cell provider said the exposure was linked to a third-party platform, and was evaluating whether it needs to notify customers.

Customers say Trump Mobile is leaking their personal information

Trump Mobile is leaking customers’ email and home addresses, but has not responded to people alerting the company of the data exposure, according to two YouTubers who said they verified that their leaked data is authentic.

US cyber agency CISA exposed reams of passwords and cloud keys to the open web

The federal cybersecurity agency left plaintext passwords in a spreadsheet uploaded to a public GitHub repository, per a report by independent journalist Brian Krebs.

A hotel check-in system left a million passports and driver’s licenses open for anyone to see

The tech company that maintains the hotel check-in system set its cloud storage to public, allowing anyone to access customers’ data without a password.

U.S. bank disclose security lapse after sharing customer data with AI app

The bank said the security lapse was due to the use of an “unauthorized” AI software app.

Money transfer app Duc exposed thousands of driver’s licenses and passports to the open web

An exposed Amazon-hosted server allowed anyone to access reams of customer data without needing a password.

Indian pharmacy chain giant exposed customer data and internal systems

A backend flaw in web admin dashboards used by one of India’s largest pharmacy chains, exposed thousands of online pharmacy orders.

UStrive security lapse exposed personal data of its users, including children

The online mentoring site UStrive exposed email addresses, phone numbers, and other non-public information to other logged-in users. The nonprofit told TechCrunch that the issue is now fixed, but wouldn’t commit to alerting affected individuals.

How a hacking campaign targeted high-profile Gmail and WhatsApp users across the Middle East

The phishing campaign targeted users on WhatsApp, including an Iranian-British activist, and stole the credentials of a Lebanese cabinet minister and at least one journalist.