A security researcher discovered that a popular Content Delivery Network (CDN) was serving cached responses that exposed private user data at scale. By conducting mass reconnaissance and analyzing cache behaviors, the researcher identified that the CDN was returning sensitive information to unauthorized users due to improper cache controls and response header misconfigurations. This vulnerability allowed attackers to access confidential data simply by refreshing pages or manipulating request headers, highlighting the risks of relying on default CDN settings for sensitive web applications.
In a separate incident, another researcher found that a web application's admin dashboard was accessible without any hacking or exploitation, due to exposed APIs and missing authorization checks. By identifying an API subdomain with publicly available documentation, the researcher was able to chain together several misconfigurations, escalating privileges from a normal visitor to full administrator access. Both cases underscore the critical importance of proper configuration and access controls in web infrastructure, as seemingly minor oversights can lead to significant data exposure and privilege escalation risks.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A security researcher identified a vulnerability in a popular CDN during large-scale reconnaissance of a production asset. Cached responses failed to properly respect authentication, exposing sensitive user data to unauthorized users, and the issue was mapped through historical endpoint analysis, JavaScript scraping, and automated header diffing.
A security researcher discovered a web application with an exposed API subdomain, publicly accessible API documentation, and missing authentication and authorization checks. Chained misconfigurations allowed privilege escalation from a normal visitor to administrator access without malware, brute force, or a software exploit.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.