Crazy Security vulnerability with billion dolla...
reverse engineered a billion dollar legal AI tool and found over 100,000 confidential files with zero authentication for this person found a massive vulnerability in a startup called Filevine, which is worth $1 billion. They found a subdomain margolist.filevine.com basically got access to this company's box API because they had a maximum access, fully scoped admin token to their entire box file system, including all confidential files, logs and user information. Millions of the most sensitive documents, documents protected by court orders. This is a privacy nightmare.
Summary
A significant security vulnerability was discovered in the AI startup Filevine, exposing over 100,000 confidential files due to a lack of authentication. The issue arose from a subdomain that granted access to the company's Box API with a fully scoped admin token, compromising sensitive documents protected by court orders.
Tags
Save videos. Search everything.
Build your personal library of inspiration. Find any quote, hook, or idea in seconds.
Create Free Account No credit card required