Cybersecurity News Hub
No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
No Result
View All Result
Cybersecurity News Hub
No Result
View All Result
Home Data Breach

26 million CVs were exposed when a recruiting software firm left a misconfigured Azure container open – cybersecurity experts warn it’s an easy mistake that’s becoming far too common

Cyberinchief by Cyberinchief
November 11, 2025
Reading Time: 3 mins read
0
26 million CVs were exposed when a recruiting software firm left a misconfigured Azure container open – cybersecurity experts warn it’s an easy mistake that’s becoming far too common



Security researchers have uncovered a misconfigured recruitment database leaking almost 26 million files, and security experts have warned it’s a trend that’s becoming far too common.

According to analysis from Cybernews, TalentHook, an online applicant tracking platform connecting HR departments with people looking for work, had left a misconfigured Azure Blob storage container open.

As a result, the resumes of millions of US citizens, including their full names, email addresses, phone numbers, education details, professional details, and employment history were exposed.

RELATED POSTS

UK Hospital Asks Court to Stymie Ransomware Data Leak

These five countries recorded the most third-party data breaches last year

LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net

“The detailed personal information in the exposed resumes enables attackers to conduct highly targeted phishing campaigns,” the Cybernews team said.

“Email addresses and phone numbers can be used in phishing emails, SMS scams, or fraudulent job offers, tricking individuals into revealing sensitive information such as ID scans or banking details.”

The data could be a boon for cybercriminals looking to snare unsuspecting jobseekers, researchers have warned. In recent months, groups such as the North Korean state-sponsored Lazarus group have been specifically targeting jobseekers.

Research earlier this year showed the group has targeted victims using LinkedIn, for example, or by posing as recruiters and approaching targets via email and WhatsApp.

Sign up today and you will receive a free copy of our Future Focus 2025 report – the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives

Sharpen up on storage configurations

Tim Mackey, head of software supply chain risk at Black Duck, said the incident shows the huge risks posed by easily overlooked misconfigurations and urged enterprises to sharpen up processes.

Buy JNews
ADVERTISEMENT

“Misconfigured systems, VMs, containers, micro-services, and data stores are nothing new,” he said.

“For example, the sample of the exposed data for this breach masks key identifiable information, such as email addresses and cell phone numbers, indicating that encryption of those elements wasn’t a priority or that an unsecured API was also part of the breach.”

Dray Agha, senior manager of security operations at Huntress, echoed Mackey’s comments, noting that incidents like these are becoming increasingly common.

“Misconfigured cloud storage (like the unsecured Azure container in this case) remains an alarmingly common yet preventable issue, especially in sectors handling highly personal information,” said Agha.

“Organizations must implement rigorous configuration audits, enforce least-privilege access controls, and conduct continuous monitoring to prevent such massive exposures of stored personal data.”

The Cybernews researchers said they have contacted TalentHook, and advised the company to change the access controls to restrict public access and secure the container, and to update permissions to ensure that only authorized users or services have the necessary access.

Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.

MORE FROM ITPRO



Source link

Tags: AzureCommoncontainerCVscybersecurityEASYExpertsExposedFirmleftmillionmisconfiguredmistakeopenrecruitingSoftwarewarn
ShareTweetPin
Cyberinchief

Cyberinchief

Related Posts

UK Hospital Asks Court to Stymie Ransomware Data Leak
Data Breach

UK Hospital Asks Court to Stymie Ransomware Data Leak

December 8, 2025
These five countries recorded the most third-party data breaches last year
Data Breach

These five countries recorded the most third-party data breaches last year

December 8, 2025
LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net
Data Breach

LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net

December 7, 2025
Rethinking the CIO-CISO Dynamic in the Age of AI
Data Breach

Rethinking the CIO-CISO Dynamic in the Age of AI

December 6, 2025
NHS supplier hit with £3m fine for security failings that led to attack
Data Breach

NHS supplier hit with £3m fine for security failings that led to attack

December 6, 2025
HHS Outlines AI Road Map Amid Major Department Overhaul
Data Breach

HHS Outlines AI Road Map Amid Major Department Overhaul

December 5, 2025
Next Post
NIGERIAN TEENAGE SCAMMER ARRESTED BY THE FBI | SAPPHIRE EGEMASI THE DOCUMENTARY

NIGERIAN TEENAGE SCAMMER ARRESTED BY THE FBI | SAPPHIRE EGEMASI THE DOCUMENTARY

🛡️ EMRS 2025 ICT | Cyber Security (साइबर सुरक्षा) Full Class | PGT, TGT, Warden, JSA, Nurse | CK Sir

🛡️ EMRS 2025 ICT | Cyber Security (साइबर सुरक्षा) Full Class | PGT, TGT, Warden, JSA, Nurse | CK Sir

Recommended Stories

A Day in the Life of Cyber Security | SOC Analyst | Penetration Tester | Cyber Security Training

A Day in the Life of Cyber Security | SOC Analyst | Penetration Tester | Cyber Security Training

October 3, 2025
Securonix: Adding Threat Intelligence to the Mix

Securonix: Adding Threat Intelligence to the Mix

October 26, 2025
SMS Pools and what the US Secret Service Really Found Around New York

SMS Pools and what the US Secret Service Really Found Around New York

October 6, 2025

Popular Stories

  • Allianz Life – 1,115,061 breached accounts

    Allianz Life – 1,115,061 breached accounts

    0 shares
    Share 0 Tweet 0
  • Prosper – 17,605,276 breached accounts

    0 shares
    Share 0 Tweet 0
  • साइबर अपराध | Illegal Payment Gateway & Rented Bank Accounts | MAMTA CHOPRA

    0 shares
    Share 0 Tweet 0
  • Miljödata – 870,108 breached accounts

    0 shares
    Share 0 Tweet 0
  • Snowflake Data Breach Explained: Lessons and Protection Strategies

    0 shares
    Share 0 Tweet 0

Search

No Result
View All Result

Recent Posts

  • Top 5 Mobile App Security Threats Leaders Must Prepare for in 2026
  • Microsoft On Women In Cybersecurity At Black Hat Europe 2025 In London
  • Polisi kembali ungkap sindikat Cyber Crime kejahatan Internasional – iNews Malam 09/03

Categories

  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos

Newsletter

© 2025 All rights reserved by cyberinchief.com

No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us

© 2025 All rights reserved by cyberinchief.com

Newsletter Signup

Subscribe to our weekly newsletter below and never miss the latest News.

Enter your email address

Thanks, I’m not interested