Tech and AINaukri exposed recruiter email addresses, researcher says

Naukri exposed recruiter email addresses, researcher says

-


Naukri.com, a popular Indian employment website, has fixed a bug that exposed the email addresses of recruiters using its platform to search and hire talent online.

The issue, discovered by security researcher Lohith Gowda, affected the API that Naukri used on its Android and iOS apps. The API exposed the email addresses of recruiters visiting profiles of potential candidates on Naukri’s platform. The issue did not appear to affect the company’s website.

“The exposed recruiter email IDs can be used for targeted phishing attacks, and recruiters may receive excessive unsolicited emails and spam,” Gowda told TechCrunch.

He added that exposed email IDs could be added to public breach databases or spam lists, and mass email address scraping could lead to automated bot abuse or scams.

TechCrunch verified the exposure after the researcher shared details about the bug. The researcher confirmed to TechCrunch that the issue was fixed earlier this week, which Naukri corroborated on Friday.

“All identified enhancements are implemented, ensuring our systems remain updated and resilient,” Alok Vij, IT infrastructure head at Naukri’s parent company InfoEdge, told TechCrunch over email. “Our teams have not detected any usual activity that affects the integrity of user data.”

Founded in March 1997, Naukri.com is India’s top classified recruitment website, helping connect recruiters, employers, and job seekers. Apart from India, the site exists in the Middle East as Naukrigulf.com.

“Certain features of our recruiter profiles are designed to be public to enable users to know who has access to their profile(s). We conduct regular audits and security assessments,” said Vij.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest news

ChatGPT Evaluates Ripple Price Predictions: How Viable Is XRP at $100?

TL;DR The XRP Army, arguably the loudest niche of the cryptocurrency community, frequently posts about the asset’s market potential,...

Fujifilm’s X Half, a New OnePlus Tablet, and Fender’s GarageBand Rival—Your Gear News of the Week

This week, Fujifilm announced a new digital half-frame compact camera called the X Half. Like half-frame film cameras,...

US Seizes $868K in Crypto From Dating Scam That Drained Wallets

Federal agents just seized $868K in crypto after busting a slick romance-fueled scam that funneled victims into fake...

UK wants more crypto user data just as trust in KYC takes new hit

New U.K. rules could mean more...

Advertisement

What is Mistral AI? Everything to know about the OpenAI competitor

Mistral AI, the French company behind AI assistant Le Chat and several foundational models, is officially regarded as...

Bitcoin and Ethereum ETFs See $1 Billion in One Day

Investors aren’t easing off the gas. Bitcoin and Ethereum ETFs just brought in over $1 billion in combined...

Must read

ChatGPT Evaluates Ripple Price Predictions: How Viable Is XRP at $100?

TL;DR The XRP Army, arguably the loudest niche of...

You might also likeRELATED
Recommended to you