Thursday , June 11 2026
red circle

Data broker exposes 600K+ passwordless sensitive files online

SL Data Services/Propertyrec, an information research provider exposes a non-password-protected database containing more than 600K records according to the security researcher Jeremiah Fowler. The dataset contains over 713 GB records including vehicle records, property ownership reports and court records.

Jeremiah Fowler said, around 95% of the limited sample of documents were The “background checks” included full names, addresses, phone numbers, email addresses, employment details, family members, social media accounts, and criminal records. I discovered that some individuals with unique names shared the same name and home address found in these checks.

Dahua patches multiple critical vulnerabilities in its products

A security notice has revealed serious flaws in some Dahua products. Network admins need to fix these issues fast. The...
Read More
Dahua patches multiple critical vulnerabilities in its products

South Korea fines Coupang Record $409 mln fine for data leak

South Korea's privacy regulator said on Thursday (June 11) that the country will fine e-commerce giant Coupang 625 billion won...
Read More
South Korea fines Coupang Record $409 mln fine for data leak

ShinyHunters claim stolen data from 100+ org via oracle PeopleSoft servers

Oracle PeopleSoft servers are under attack in ongoing data theft by the ShinyHunters gang, which claim to have stolen data...
Read More
ShinyHunters claim stolen data from 100+ org via oracle PeopleSoft servers

Security Update: RoguePlanet, BitLocker Bypass, Chromium Zero-Day, and More Critical Threats Uncovered

Cybersecurity experts found several serious flaws this week in Windows, Chromium, OpenSSL, Microsoft Exchange, and ServiceNow. Some of these flaws...
Read More
Security Update: RoguePlanet, BitLocker Bypass, Chromium Zero-Day, and More Critical Threats Uncovered

73 Microsoft Packages Compromised in Password Stealer Attack

GitHub disabled 73 repositories in four Microsoft groups: Azure, Azure-Samples, Microsoft, and MicrosoftDocs. Each repo now shows GitHub’s “This repository...
Read More
73 Microsoft Packages Compromised in Password Stealer Attack

New Windows Defender ‘RoguePlanet’ zero-day grants SYSTEM privileges

A security expert shared a new Microsoft Defender vulnerability called "RoguePlanet" only hours after Microsoft fixed two earlier problems in...
Read More
New Windows Defender ‘RoguePlanet’ zero-day grants SYSTEM privileges

Microsoft June Patches 200 Vulnerabilities including 3 zero days

Microsoft's June 2026 Patch Tuesday updates fix about 200 security flaws found in the company's products. None of the flaws fixed...
Read More
Microsoft June Patches 200 Vulnerabilities including 3 zero days

World’s first wind power underwater data center is now live

The first business underwater data center run by offshore wind has started working near Shanghai. Submerged 10 metres under the...
Read More
World’s first wind power underwater data center is now live

VMware Fixed Multiple Flaws Allow Attackers to Inject Malicious Scripts

Broadcom has revealed three stored cross-site scripting (XSS) flaws that affect VMware Cloud Foundation Operations and some other products. They...
Read More
VMware Fixed Multiple Flaws Allow Attackers to Inject Malicious Scripts

CVE-2026-50751
Check Point VPN 0-day Flaw Exploited in the Wild 

Check Point Research found that CVE-2026-50751, a serious flaw in Check Point Remote Access VPN and Mobile Access, is being...
Read More
CVE-2026-50751  Check Point VPN 0-day Flaw Exploited in the Wild 

According to the researcher, the exposed dataset suggest the company operates a network of 16 different websites. For example, Propertyrec — a website that lists property and real estate data — was mentioned in the database’s name. After a responsible disclosure, The company restricted the public access over one week later, said Jeremiah Fowler.

Court records and sex offender statuses are typically public in the US, but this data could be merged with other information to create detailed profiles of individuals and their families, aiding criminals in targeted phishing and social engineering attacks. Another concern is impersonation, where a criminal uses the identity of someone whose personal information was leaked in a background check.

Using personally identifiable information (PII), like customer names and locations, in filenames for internal document storage can make file organization easier, but it’s not secure. If a data breach occurs, these filenames can lead to privacy risks, even more so if the files aren’t encrypted. Unauthorized users might access PII just by viewing the directory or file metadata without needing to open the file.

This discovery follows the August 2024 data breach of National Public Data, which exposed the personal information of millions. Hackers accessed the company’s systems and put the stolen data, including names, addresses, and phone numbers, for sale on the dark web for $3.5 million USD. The dataset included personal information of citizens from the US, Canada, and the UK.

The register reported, ” The info service provider eventually closed up the S3 bucket, says Fowler, although he never received any response. The Register also reached out to SL Data Services for comment and did not hear back.”

Check Also

flaw

Cisco SD-WAN Flaw Exploited and Trend Micro Flaws Allows to Security Bypass

Trend Micro’s Deep Security Agent for Linux has a design flaw. This issue lets a …