Cybersecurity researcher Jeremiah Fowler reported to Website Planet that he found a non-password-protected 1.2 TB dataset containing over 3 million records from Builder.ai, a London company that provides AI software and app development solutions without requiring coding skills.
Jeremiah Fowler claimed the unsecured database contained 3,077,542 records, totaling 1.29 TB. A sample of the documents revealed customer proposals, NDA agreements, invoices, tax documents, email screenshots, and internal images.
By infosecbulletin
/ Friday , May 9 2025
YouTube has restricted access to at least four Bangladeshi television channels in India following a takedown request from the Indian...
Read More
By infosecbulletin
/ Friday , May 9 2025
Microsoft has fixed critical vulnerabilities in its core cloud services, including Azure Automation, Azure Storage, Azure DevOps, and Microsoft Power...
Read More
By infosecbulletin
/ Thursday , May 8 2025
The cyber threat landscape is rapidly changing, with a notable increase in ransomware activity in April 2025, driven by the...
Read More
By infosecbulletin
/ Thursday , May 8 2025
SonicWall has released patches for three security flaws in SMA 100 Secure Mobile Access appliances that could allow remote code...
Read More
By infosecbulletin
/ Thursday , May 8 2025
From April 2024 to April 2025, Flashpoint analysts noted that the financial sector was a major target for threat actors,...
Read More
By infosecbulletin
/ Thursday , May 8 2025
Cisco has issued a security advisory for a critical vulnerability in its IOS XE Software for Wireless LAN Controllers (WLCs)....
Read More
By infosecbulletin
/ Wednesday , May 7 2025
Attackers linked to the Play ransomware operation deployed a zero-day privilege escalation exploit during an attempted attack against an organization...
Read More
By infosecbulletin
/ Wednesday , May 7 2025
Hackers are exploiting an unauthenticated remote code execution vulnerability in the Samsung MagicINFO 9 Server to take control of devices...
Read More
By infosecbulletin
/ Tuesday , May 6 2025
CISA added the Langflow vulnerability, CVE-2025-3248 (CVSS score 9.8), to its Known Exploited Vulnerabilities catalog. Langflow is a popular tool...
Read More
By infosecbulletin
/ Tuesday , May 6 2025
Google has released its monthly Android security updates, addressing 46 vulnerabilities, including one that has been actively exploited. CVE-2025-27363 (CVSS...
Read More
He said another two critical documents contained access and configuration details for two cloud storage databases, including secret access keys. However, if these access keys were misused, they could expose sensitive data.
The database and its documents belong to Engineer.ai and Builder.ai, which are the same company that rebranded in 2019. Builder.ai is a London-based tech firm that offers human-assisted AI for app development, with offices across the US, Asia, Europe, and the Middle East.
Jeremiah Fowler said After a responsible disclosure i got , “unfortunately it’s taking longer than we’d like due to some complexities with dependent systems” the replay from the company.
In a 2023 press release, Builder.ai announced it secured over $250 million in Series D funding, led by the Qatar Investment Authority, bringing its total funding to over $450 million. That year, Builder.ai was ranked #3 in Fast Company’s list of the World’s Most Innovative Companies in the Artificial Intelligence category.
Fowler advised encrypting data and creating an incident response plan with access control to handle breaches primarily.
“Workshop on Cybersecurity Awareness and Needs Analysis” held at BBTA