[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help] 

Status: Not Logged In; Sign In

The Whopping Lie Behind Huge, New Pension Liability Imposed By Springfield On Chicago

Families Are Fascist

"Operation Gladio is Alive and Well" NATO"s secret terrorist army EXPOSED

White Swan Collapse Underway: Ed Dowd Warns 50% Stock Crash

To Kill An Operation Mockingbird: Tulsi Goes To War With The CIA's Propaganda Yobbos

Huge Drug And Weapons Haul In French Polynesia Echoes Kash Patel's Warnings

⚠️ALERT: TRUMP HAS ACTIVATED 11.3 – Law Of War Manual

IDF Soldier: “We Were ORDERED To Stand Down On October 7th!”

Michael Snyder: The New York Declaration” Could Potentially Change Everything

Hillary Clinton calls for the repeal of Section 230 so that platforms can moderate Americans' speech.

Sydney Sweeney Has Great Jeans - Outrage AI Parody Song

Alarming Seismic Instability Along The East Coast, The New Madrid Fault Zone And The West Coast

Whitney Webb: "What's Happening Is Deeper Than Blackmail"

Matt Taibbi: The New York Times Can't Stop Sucking

Canada is now an Anti-Christian Country? When did this happen?

Dr Horse Predicts Food Prices Might Double in 2026

Krasheninnikov Volcano Erupts for the First Time in 600 Years — and It May Be Linkd to a Massive Earthquake

Shocking Chart Exposes America's "Civilizational Crisis"; A Nation In Freefall Without Immediate Course Correction

Watch: Sydney Sweeney Goes 'John Wick-Style' With Handgun

Sen. Blackburn To Introduce Bills To Root Out 'Embedded' Foreign Interest

China Builds a Gold-Based Alternative to the Dollar System, Modeled on Dollar Architecture

Why the U.S. Buys So Much Nuclear Fuel From Russia | WSJ

Orbán Says Hungary, Poland, Slovakia & Czechs Can Block EU Budget With United Front

What if you drink Water at Night?

Since 2/2021 we have added 5.89 million to this survey which is 19.6% growth. Disaster!

Trump Admin Saves Jobs, Kicks 1500 Non-English-Speaking Truckers Off the Road

Indians & Nepalese Are The World's Most Voracious Mobile Data Users

Doc's favorite movie when we were kids...

Fauci Meme

Hey Horse!


World News
See other World News Articles

Title: McDonald's McHire AI Bot Just Exposed The Personal Data Of 64 McMillion People
Source: [None]
URL Source: https://www.zerohedge.com/markets/m ... sonal-data-64-mcmillion-people
Published: Jul 25, 2025
Author: Tyler Durden
Post Date: 2025-07-25 13:49:30 by Horse
Keywords: None
Views: 85
Comments: 1

A security lapse in McDonald’s job application system could have exposed the personal details of around 64 million people — all because someone used the password “123456", according to Tom's Hardware.

"That's amazing. We've got the same combination on our luggage!"

Researchers Ian Carroll and Sam Curry discovered serious flaws in McHire, the chatbot developed by Paradox.ai and used by most McDonald’s franchises for recruitment. While poking around, they found that internal accounts used by Paradox staff were protected by one of the most commonly guessed passwords in the world: “123456.”

The report says Carroll compared it to his own teenage mistake of using “1234” on a forum account. “That’s slightly better than the password I used, I guess,” he wrote, “but not enough to justify its use decades after most people realized that using weak passwords is a bad idea.”

Using that flimsy credential, the researchers gained administrative access — though initially only to a test restaurant account tied to Paradox employees. That let them explore the system, but didn’t prove any real-world risk. The real issue came when they found a second vulnerability: an insecure direct object reference (IDOR) flaw in the McHire API.

That bug let them pull sensitive data from any chat-based application submitted to McDonald’s — names, email addresses, phone numbers, home addresses, application details, and even login tokens that allowed full access to user chats and potentially more.

Paradox once boasted that 90% of McDonald’s franchises relied on McHire for hiring, though that claim has since quietly vanished from its blog.

To put things in context: Paradox raised $200 million in 2020. McDonald’s is worth over $200 billion. And yet a system handling tens of millions of people’s private information was essentially protected by the digital equivalent of a sticky note on a monitor.

The only silver lining? Carroll and Curry say the vulnerabilities were patched within 24 hours of being reported. With any luck, McDonald’s and Paradox will aim for better cybersecurity hygiene going forward — maybe even something a little more secure than “123456.”


Poster Comment:

France Will Recognize Palestinian State - US-Israeli Backlash Ensues

Netanyahu says recognition "rewards terror"-- but terror marked Israel's path to statehood too

https://www.zerohedge.com/geopolitical/france-will-recognize-palestinian-state-us- israeli-backlash-ensues

Post Comment   Private Reply   Ignore Thread  


TopPage UpFull ThreadPage DownBottom/Latest

#1. To: Horse (#0)

"Dumb" vulnerabilities may be intentional.

A rainbow coalition against Jews doesn't require Whites or Pro-Whites. It can be just as brown or anti-white as you like.

Prefrontal Vortex  posted on  2025-07-25   16:50:09 ET  Reply   Trace   Private Reply  


TopPage UpFull ThreadPage DownBottom/Latest


[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help]