Bluspark Global, a New York-based shipping technology provider, remediated multiple critical security weaknesses in its Bluvoyix shipping and supply-chain platform after a researcher found the system was effectively exposed to the public internet and could have enabled unauthorized access to sensitive customer data. The issues risked exposing decades of shipment records for hundreds of large companies that use the platform across sectors such as retail, grocery, and manufacturing, and could have allowed remote interaction with Bluvoyix’s shipping software.
Security researcher Eaton Zveare reported finding five flaws, including the use of plaintext passwords and an unauthenticated API that could allow retrieval of user account records (including administrator credentials) and creation of new administrative accounts without authentication. Reporting indicated that disclosure was complicated by the lack of a clear security contact or bug reporting channel; Bluspark said the issues have been resolved and it plans to implement a formal bug disclosure program.

Map this exposure pattern across your cloud, code, and identities.
5 events from the most recent confirmed update back to the earliest known activity.
In its response through counsel, Bluspark said there was no indication that customers were affected or that the reported vulnerabilities had been maliciously exploited. This statement accompanied the company's remediation of the issues.
By mid-January 2026, Bluspark said it had resolved the reported vulnerabilities in its Bluvoyix platform, which had risked unauthorized access to customer data and shipping systems. The company also said it planned to introduce a formal vulnerability disclosure or bug reporting program.
Before publication, TechCrunch contacted Bluspark and demonstrated the seriousness of the issue by including part of a password in an email. Bluspark then responded through outside counsel and began addressing the reported vulnerabilities.
After finding the vulnerabilities, Zveare was unable to find clear security disclosure channels at Bluspark and escalated the matter by involving the Maritime Hacking Village and TechCrunch to reach the company. This disclosure effort occurred before Bluspark began remediation.
In October 2025, security researcher Eaton Zveare identified multiple vulnerabilities in Bluspark Global's Bluvoyix shipping platform, including an unauthenticated API, plaintext credential exposure, and paths to administrative access. The flaws could have exposed sensitive customer data, shipment records, and allowed unauthorized creation of admin accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.