[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help] 

Status: Not Logged In; Sign In

Charlie Kirk has been shot

Elon Musk Commits $1 Million To Murals Of Iryna Zarutska Nationwide, Turning Public Spaces Into Culture War Battlegrounds

Trump's spiritual advisor, Paula White: "To say no to President Trump would be saying no to God."

NETHERLANDS: Young natives are hunted and beaten on the streets by savage migrants

Female Police Officers Arrest Violent Man The Ponytail Police In Action

Lighter than Hare - Restored Classic Bugs Bunny

You'll Think Twice About Seeing Your Medical Doctor After This! MUST SEE

Los Angeles man creates glass that withstands hammers, saving jewelry from thieves.

This is F*CKING DISGUSTING... [The news MSM wishes you didn't see]

Nepal's Gen Z protest against Govt in Kathmandu Explained In-depth Analysis

13 Major World War III Developments That Have Happened Just Within The Past 48 Hours

France On Fire! Chaos & Anarchy grip Paris as violent protesters clash with police| Macron to quit?

FDA Chief Says No Solid Evidence Supporting Hepatitis B Vaccine At Birth

"Hundreds of Bradley Fighting Vehicles POURING into Chicago"

'I'll say every damn name': Marjorie Taylor Green advocates for Epstein victims during rally

The long-awaited federal crackdown on illegal alien crime in Chicago has finally arrived.

Cash Jordan: ICE BLOCKS 'Cartel Caravan'... HAULS 'Army of Illegals' BACK TO MEXICO

Berenson On Black Violence, Woke Lies, & Right-Wing Rage

What the Professor omitted about the collapse of the American Empire.

Israel Tried to Kill Hamas in Qatar — Here’s What REALLY Happened

Katie Hopkins: Laurence Fox and my beaver. NOT FOR THE WEAK

Government Accidentally Reveals Someone Inside Twitter Fabricated 'Gotcha' Accounts To Frame Conservative Firebrand

The Magna Carta Of 2022 – Worldwide Declaration of Freedom

Hamas Accuses Trump Of A Set-Up In Doha, After 5 Leaders Killed In Israeli Strike

Cash Jordan: Angry Voters Go “Shelter To Shelter”... EMPTYING 13 Migrant Hotels In 2 Hours

Israel targets Hamas leadership in attack on Qatar’s Doha, group says no members killed

Israeli Finance Minister Bezalel Smotrich said on Monday that villages in the Israeli-occupied West Bank should look like cities in Gaza

FBI Arrests 22 Chinese, 4 Pharma Companies, Preventing Disaster That Could Kill 70 Million Americans

911 Make Believe

New CLARITY Act Draft Could Shield Crypto Developers From Past Liability


World News
See other World News Articles

Title: McDonald's McHire AI Bot Just Exposed The Personal Data Of 64 McMillion People
Source: [None]
URL Source: https://www.zerohedge.com/markets/m ... sonal-data-64-mcmillion-people
Published: Jul 25, 2025
Author: Tyler Durden
Post Date: 2025-07-25 13:49:30 by Horse
Keywords: None
Views: 336
Comments: 1

A security lapse in McDonald’s job application system could have exposed the personal details of around 64 million people — all because someone used the password “123456", according to Tom's Hardware.

"That's amazing. We've got the same combination on our luggage!"

Researchers Ian Carroll and Sam Curry discovered serious flaws in McHire, the chatbot developed by Paradox.ai and used by most McDonald’s franchises for recruitment. While poking around, they found that internal accounts used by Paradox staff were protected by one of the most commonly guessed passwords in the world: “123456.”

The report says Carroll compared it to his own teenage mistake of using “1234” on a forum account. “That’s slightly better than the password I used, I guess,” he wrote, “but not enough to justify its use decades after most people realized that using weak passwords is a bad idea.”

Using that flimsy credential, the researchers gained administrative access — though initially only to a test restaurant account tied to Paradox employees. That let them explore the system, but didn’t prove any real-world risk. The real issue came when they found a second vulnerability: an insecure direct object reference (IDOR) flaw in the McHire API.

That bug let them pull sensitive data from any chat-based application submitted to McDonald’s — names, email addresses, phone numbers, home addresses, application details, and even login tokens that allowed full access to user chats and potentially more.

Paradox once boasted that 90% of McDonald’s franchises relied on McHire for hiring, though that claim has since quietly vanished from its blog.

To put things in context: Paradox raised $200 million in 2020. McDonald’s is worth over $200 billion. And yet a system handling tens of millions of people’s private information was essentially protected by the digital equivalent of a sticky note on a monitor.

The only silver lining? Carroll and Curry say the vulnerabilities were patched within 24 hours of being reported. With any luck, McDonald’s and Paradox will aim for better cybersecurity hygiene going forward — maybe even something a little more secure than “123456.”


Poster Comment:

France Will Recognize Palestinian State - US-Israeli Backlash Ensues

Netanyahu says recognition "rewards terror"-- but terror marked Israel's path to statehood too

https://www.zerohedge.com/geopolitical/france-will-recognize-palestinian-state-us- israeli-backlash-ensues

Post Comment   Private Reply   Ignore Thread  


TopPage UpFull ThreadPage DownBottom/Latest

#1. To: Horse (#0)

"Dumb" vulnerabilities may be intentional.

A rainbow coalition against Jews doesn't require Whites or Pro-Whites. It can be just as brown or anti-white as you like.

Prefrontal Vortex  posted on  2025-07-25   16:50:09 ET  Reply   Trace   Private Reply  


TopPage UpFull ThreadPage DownBottom/Latest


[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help]