| |
A Blackstone real estate company exposed SSN digits, DOBs, addresses and more
A security researcher discovered that Beam Living, a Blackstone portfolio company, exposed sensitive personal information including Social Security number digits, dates of birth, addresses, and other applicant data through an unsecured GraphQL API endpoint. The vulnerability was discovered while the researcher was applying for an apartment lease and noticed that GraphQL queries contained personal data that could be easily accessed by querying the API with just an applicant's email address.
Read Full Article →
← More Tech news