Laughing Hyena
  • Home
  • Hyena Games
  • Esports
  • NFT Gaming
  • Crypto Trends
  • Game Reviews
  • Game Updates
  • GameFi Guides
  • Shop
Tag:

EXPOSED

Highly Sensitive Medical Cannabis Patient Data Exposed by Unsecured Database
Gaming Gear

Highly Sensitive Medical Cannabis Patient Data Exposed by Unsecured Database

by admin August 20, 2025


As legal cannabis has expanded around the United States for both recreational and medical use, companies have amassed troves of data about customers and their transactions. People who have applied for medical marijuana cards have had to share particularly personal health data to qualify. For some patients in Ohio who use medical weed, a recent data exposure could impact their sensitive information.

Security researcher Jeremiah Fowler found a publicly accessible database in mid-July that appeared to contain medical records, mental health evaluations, physician reports, and images of IDs like driver’s licenses for people seeking medical cannabis cards. The 323-GB trove stored close to a million records, including Social Security numbers, email addresses, physical addresses, dates of birth, and medical data—all organized by name.

Based on information that seemed to describe specific employees and business partners, Fowler suspected that the data belonged to the Ohio-based company Ohio Medical Alliance LLC, which goes by the name Ohio Marijuana Card. Fowler contacted the company on July 14; when he checked the database the next day, it had been secured and was no longer publicly accessible online. Fowler did not receive a response about his submission.

Ohio Medical Alliance did not answer WIRED’s questions about Fowler’s findings. At one point, though, the company’s president, Cassandra Brooks, wrote in an email: “I need time to investigate this alleged incident. We take data security very seriously and are looking into this matter.”

“There were physicians’ reports that would say what the underlying problem was—whether it was anxiety, cancer, HIV, or something else. In some cases, the applicants would submit their own medical records as proof” of their qualifying condition, Fowler tells WIRED. “I saw identification documents from lots of states, from everywhere. And I even saw offender release cards, which are basically IDs for people who just got out of prison that they submitted as proof of identity to get a medical marijuana card.”

Fowler says that most of the files in the database were image formats like PDFs, JPGs, and PNGs. One CSV plaintext document called “staff comments” appeared to be an export of internal communications, appointment histories, notes about clients, and application status. That file also contained more then 200,000 email addresses of Ohio Medical Alliance employees, business associates, and customers.

Databases that are misconfigured and have inadvertently been left publicly exposed on the open internet are a common problem online in spite of efforts to raise awareness about the mistake and its privacy implications.



Source link

August 20, 2025 0 comments
0 FacebookTwitterPinterestEmail
Representational image of a cybercriminal
Gaming Gear

Public database exposed 184 million credentials including Microsoft, Facebook, Snapchat, and government account logins

by admin June 18, 2025



  • The Sitecore CMS had an account with a hardcoded password
  • Threat actors could use it to upload arbitrary files, achieving RCE
  • Thousands of endpoints are potentially at risk

Sitecore Experience Platform, an enterprise-level content management system (CMS) carried three vulnerabilities which, when chained together, allowed threat actors full takeover of vulnerable servers, experts have warned.

Cybersecurity researchers watchTowr found the first flaw is a hardcoded password for an internal user – just one letter – ‘b’ – making it super easy to guess.

The account does not have admin privileges, but watchTowr found malicious users could authenticate via an alternate login path, which would give them authenticated access to internal endpoints.


You may like

Patching the flaws

This sets the stage for the exploitation of the second flaw, described as a “Zip Slip” in the Sitecore Upload Wizard.

In a nutshell, the now-authenticated attackers can upload malicious files due to insufficient path sanitation, and the way Sitecore maps paths. As a result, they can write arbitrary files in the webroot.

These two issues alone could be enough to cause some serious damage on the compromised server, but the problems don’t stop there.

If the website has the Sitecore PowerShell Extensions (SPE) module installed, which is commonly bundled with SXA, attackers can upload arbitrary files to specific paths, bypassing extension or location restrictions and resulting in a “reliable RCE”.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

All Sitecore versions from 10.1 to 10.4 are apparently vulnerable, which translates to roughly 22,000 publicly exposed instances, at press time – but just because they’re all accessible and running these versions, it doesn’t necessarily mean they’re all vulnerable.

“Sitecore is deployed across thousands of environments, including banks, airlines, and global enterprises — so the blast radius here is massive,” watchTowr CEO Benjamin Harris told BleepingComputer.

“And no, this isn’t theoretical: we’ve run the full chain, end-to-end. If you’re running Sitecore, it doesn’t get worse than this – rotate creds and patch immediately before attackers inevitably reverse engineer the fix.”

So far there were no reports of abuse in the wild, but a patch is available now, so users should update as soon as possible.

You might also like



Source link

June 18, 2025 0 comments
0 FacebookTwitterPinterestEmail
Wazirx, Zettai, Zensui Exposed In A Brutal Verdict Of Singapore Judge
GameFi Guides

WazirX, Zettai, Zensui Exposed in a Brutal Verdict of Singapore Judge

by admin June 18, 2025



It’s been exactly 11 months since WazirX was hacked on July 18, 2024. Rs 2,000 crore worth of crypto vanished overnight. 4.4 million users were left scrambling for answers. They waited for justice, they waited for transparency, but above all, they waited for a word, just a single word, from Nischal Shetty.

They got silence.

And now, from a courtroom thousands of miles away in Singapore, came the voice they never expected, but so desperately needed. Judicial Commissioner Kristy Tan didn’t just rule on a restructuring proposal. 

She uncovered a rotten scheme, built on lies, fake governance, and hidden control. While Indian authorities fumbled and the WazirX leadership vanished, it was a Singaporean judge who finally exposed the truth.

The Vote Was a Lie. The Scheme Was a Façade.

WazirX and Zettai put forward what they called a “user vote”—a decision-making process on how the platform should proceed post-hack. But as per Judge Kristy Tan, it was all smoke and mirrors.

“Why weren’t putative scheme creditors informed of this plan so that they could make an informed vote?”

Source: X

The scheme to restructure WazirX was dated March 12, 2025. Zensui, the secret entity operating behind Zettai, was incorporated just two days earlier. Users were never told. Even the Court wasn’t informed at a crucial hearing on May 13. What kind of ‘vote’ hides the most essential facts from the very people who are supposed to decide?

“If I not raised the questions I did yesterday,” Judge Tan stated, “would Zensui’s role have remained concealed from the Court and platform users? I strongly suspect so.”

This wasn’t incompetence, it was manipulation.

Zettai: Operating Illegally, With Full Knowledge

WazirX’s operational partner, Zettai, was declared illegal. The company had no Digital Token Service Provider (DTSP) license to run crypto services in Singapore. Shockingly, their counsel, R&T, admitted they never even intended to apply for one.

“The proposed scheme cannot be affected by Zettai without Zettai acting illegally if it does not obtain a DTSP license.”

Source: X

Operating without a license in Singapore is a criminal offense. Zettai not only violated the law, they did so knowingly. This is not mismanagement; it’s willful defiance.

Zensui: The Hidden Panama Link

But the most damning detail? Zensui, the Panama-registered entity secretly pulling the strings.

For months, users were made to believe Zettai was in charge. In reality, the court discovered that Zensui had full operational control. This deliberate concealment was, in the judge’s words, an ‘abuse of judicial process.’

Why the lies? Why the delays? The answer is heartbreakingly clear now: to buy time and avoid accountability.

Source: X

“If the scheme was sanctioned, would scheme creditors even know that despite the terms of the scheme, there was limited practical recourse against Zettai since operations had been transferred to Zensui?”

WazirX’s Blatant Non-Compliance in India Too

The betrayal didn’t stop at Singapore’s borders. Judge Tan also noted that WazirX has never registered with India’s Financial Intelligence Unit (FIU): a mandatory requirement for crypto exchanges.

So now what users have:

  • No DTSP license in Singapore.
  • No FIU-IND compliance in India.
  • No transparency to users.
  • No answers from the founder.

This is not a coincidence. This is a pattern.

Fake Townhalls. Fake Governance. Real Heartbreak.

Throughout 2024 and 2025, WazirX organized digital townhalls and conducted what they claimed were community votes. Victims clung to every update, hoping for a breakthrough. But now we know the truth: it was all theatre. A grand production to keep hope alive while the real story stayed buried.

The Singapore Court’s findings have left the Twitter community shattered. “We fought for months. And now we learn it was all fake?” wrote one user. Another said, “Kristy Tan did what no one else dared to do—she told us the truth.”

Where is Nischal Shetty?

While millions of users waited, Nischal Shetty disappeared. No statements. No townhalls. No apologies. Just silence.

For a year, users cried out. They wrote threads, contacted media, filed cases. But no response ever came from the man they once trusted.

Now, it’s a judge from another country who has finally broken the silence.

What Happens Next?

After the Judge rejected Zettai’s restructuring scheme on June 4, the company filed a formal request on June 6 seeking “further arguments” (case HC/SUM 940/2025). Under Singapore law, the same judge has until June 20 to decide whether to reverse her own decision.

But the damage is already done. The public knows the truth.

This was never a recovery plan. This was a cover-up.

The Verdict That Shook the Crypto World

In what reads more like a financial crime thriller than a court order, the Singapore Supreme Court has laid bare the reality:

  • Illegal operations by Zettai.
  • Hidden ownership through Zensui.
  • A fake vote was used to mislead 4.4 million users.
  • Zero compliance with Indian and Singaporean laws.

The hope of recovering funds from the Rs 2,000 crore WazirX hack feels even more distant now. Users are heartbroken, yes, but they are also furious. This isn’t just about crypto anymore. It’s about justice, accountability, and truth.

Also Read: Rise and Fall of WazirX: Mapping India’s Biggest Crypto Hack



Source link

June 18, 2025 0 comments
0 FacebookTwitterPinterestEmail
An abstract image of a lock against a digital background, denoting cybersecurity.
Gaming Gear

More than 3 million records, 12TB of data exposed in major app builder breach

by admin June 5, 2025



  • Passion.io, a major no-code app-building app, operated a non-password-protected database
  • The archive contained millions of records, with a total size of around 12TB
  • It was since then locked down, but users should still take care

Millions of records containing sensitive, personally identifiable information, were sitting online in yet another unencrypted, non-password-protected database, experts have warned.

Found by security researcher Jeremiah Fowler, who discovered and reported his findings to vpnMentor, the database contained 3,637,107 records, and was 12.2TB in total size.

It belongs to a company called Passion.io, a Delaware-based no-code app-building platform that allows creators, influencers, entrepreneurs, and coaches, to create websites without having any prior coding knowledge. They can also create, and sell, interactive courses.


You may like

View Deal

Locking the archive down

Fowler said that he analyzed a “limited sampling of the exposed documents” and saw internal files, images, and spreadsheet documents marked as “users” and “invoices”.

These files contained people’s names, email addresses, postal addresses, and details about payments or payouts for users and app creators.

This type of information is a treasure trove for cybercriminals. They can use it to create convincing phishing emails, tricking Passion’s users into making rash, dangerous decisions. Besides phishing, the data can be used in identity theft, wire fraud, and other types of scams.

The researcher notified Passion.io about his findings, and got a response on the same day. The database was locked down, and the company confirmed it was working on putting guardrails in place so that mishaps like this one don’t repeat.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

“We’re treating this very seriously and moving fast,” the company told Fowler.

So far, there is no evidence the information is circulating on the dark web – and it’s also not known if Passion.io is the one managing the database, or if the job was outsourced to a third party.

Without a thorough investigation, there is no way of knowing for how long the database remained open, or if any threat actors found it already.

You might also like



Source link

June 5, 2025 0 comments
0 FacebookTwitterPinterestEmail
Decrypt logo
NFT Gaming

UNDER EXPOSED EP 28 – Macro, Summer Crypto Outlook & InfoFi Overheats

by admin June 4, 2025



UNDER EXPOSED EP 28 – Macro, Summer Crypto Outlook & InfoFi Overheats

UNDER EXPOSED brings you coverage of the biggest macro news of the week impacting crypto and broader markets, with a focus on the newest trends, trades and narratives. Join hosts TylerD, Deeze, Geebz and Peter Jennings as they have longer conversations on the hottest sectors in crypto and NFTs, what is moving markets and what they’re buying and selling. Streaming live every Tuesday from 12:00 PM EST to 1:00 PM EST on YouTube and X.

Links:
https://www.rug.fm/
https://x.com/rugradio
https://linktr.ee/rugradio

Hosts:
Tweets by DeeZe
Tweets by CSURAM88
https://twitter.com/artgeebz
Tweets by Tyler_Did_It

Myriad:
https://myriad.markets
https://x.com/MyriadMarkets
https://www.instagram.com/myriadmarkets

#bitcoin #crypto #podcast





Source link

June 4, 2025 0 comments
0 FacebookTwitterPinterestEmail
terminator marching towards camera in post-apocalyptic world
Esports

AI company files for bankruptcy after being exposed as 700 human engineers

by admin June 2, 2025



A $1.5 billion AI company backed by Microsoft has shuttered after its ‘neural network’ was discovered to actually be hundreds of computer engineers based in India.

AI is all the rage right now as companies laser in on language-learning models like ChatGPT, Gemini, LLaMA and more.

However, one of these AI brands has been exposed as a total sham in a wild scam that’s going viral on social media.

‘Natasha,’ an AI app-building service from London-based Builder.ai, claimed it had the ability to use artificial intelligence to create applications. From coming up with app designs to writing code, Natasha promised to pump out programs in record time.

Article continues after ad

Builder.aiBuilder.ai boasted a fast, effective way for “anyone” to get an application fast.

Microsoft reportedly backed the ‘neural network’ with a $455 million investment, leading to a valuation of $1.5 billion… but it turns out all that cash was going toward a workforce of over 700 Indian engineers, rather than an AI.

AI app-building company exposed as hundreds of human workers

As reported by Binance, employees said the majority of labor at Builder.ai was produced by humans, with some clerical work being done using general software.

Article continues after ad

The farce lasted for eight years, getting exposed in May 2025. Builder announced bankruptcy shortly thereafter, writing in a statement on LinkedIn that it would be “entering into insolvency proceedings.”

Article continues after ad

“Despite the tireless efforts of our current team and exploring every possible option, the business has been unable to recover from historic challenges and past decisions that placed significant strain on its financial position,” the company wrote.

LinkedIn: builder.ai

Documents reviewed by Bloomberg showed that Builder also worked with VerSe, an India-based social media startup, to falsely increase its sales numbers, regularly billing each other for similar amounts between 2021 – 2024.

Sources close to the situation told Bloomberg that services weren’t actually rendered from either company for these payments — claims that VerSe has vehemently denied.

Article continues after ad

“We’re not the kind of company that is in the business of inflating revenues,” VerSe co-founder Umang Bedi said to Bloomberg, calling the accusations “baseless and false.”



Source link

June 2, 2025 0 comments
0 FacebookTwitterPinterestEmail
Decrypt logo
Crypto Trends

UNDER EXPOSED EP 26 – Moody’s and Macro, ETH Fakeout and Trading Roundtable

by admin May 21, 2025



UNDER EXPOSED EP 26 – Moody’s and Macro, ETH Fakeout and Trading Roundtable

UNDER EXPOSED brings you coverage of the biggest macro news of the week impacting crypto and broader markets, with a focus on the newest trends, trades and narratives. Join hosts TylerD, Deeze, Geebz and Peter Jennings as they have longer conversations on the hottest sectors in crypto and NFTs, what is moving markets and what they’re buying and selling. Streaming live every Tuesday from 12:00 PM EST to 1:00 PM EST on YouTube and X.

LIVE AUDIO SPACE – https://x.com/i/spaces/1ZkKzYOEazLxv

Links:
https://www.rug.fm/
https://x.com/rugradio
https://linktr.ee/rugradio

Hosts:
Tweets by DeeZe
Tweets by CSURAM88
https://twitter.com/artgeebz
Tweets by Tyler_Did_It

Myriad:
https://myriad.markets
https://x.com/MyriadMarkets
https://www.instagram.com/myriadmarkets

#bitcoin #crypto #podcast





Source link

May 21, 2025 0 comments
0 FacebookTwitterPinterestEmail

Categories

  • Crypto Trends (901)
  • Esports (682)
  • Game Reviews (633)
  • Game Updates (798)
  • GameFi Guides (896)
  • Gaming Gear (863)
  • NFT Gaming (877)
  • Product Reviews (851)
  • Uncategorized (1)

Recent Posts

  • HBAR Tumbles 3% as Institutional Investors Exit Positions
  • Tropico 7 announced for PC and consoles, and it’s coming to Game Pass on day one
  • Asus heard you like screens, so it put a curved ‘3D effect’ OLED screen on your CPU water cooler
  • SharpLink Gaming Acquista143.593 Ethereum per Oltre 500 Milioni di Dollari
  • Bitcoin’s Year-End Destination: SkyBridge Founder Stands By Bold Prediction, Here’s The Target

Recent Posts

  • HBAR Tumbles 3% as Institutional Investors Exit Positions

    August 20, 2025
  • Tropico 7 announced for PC and consoles, and it’s coming to Game Pass on day one

    August 20, 2025
  • Asus heard you like screens, so it put a curved ‘3D effect’ OLED screen on your CPU water cooler

    August 20, 2025
  • SharpLink Gaming Acquista143.593 Ethereum per Oltre 500 Milioni di Dollari

    August 20, 2025
  • Bitcoin’s Year-End Destination: SkyBridge Founder Stands By Bold Prediction, Here’s The Target

    August 20, 2025

Newsletter

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!

About me

Welcome to Laughinghyena.io, your ultimate destination for the latest in blockchain gaming and gaming products. We’re passionate about the future of gaming, where decentralized technology empowers players to own, trade, and thrive in virtual worlds.

Recent Posts

  • HBAR Tumbles 3% as Institutional Investors Exit Positions

    August 20, 2025
  • Tropico 7 announced for PC and consoles, and it’s coming to Game Pass on day one

    August 20, 2025

Newsletter

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!

@2025 laughinghyena- All Right Reserved. Designed and Developed by Pro


Back To Top
Laughing Hyena
  • Home
  • Hyena Games
  • Esports
  • NFT Gaming
  • Crypto Trends
  • Game Reviews
  • Game Updates
  • GameFi Guides
  • Shop

Shopping Cart

Close

No products in the cart.

Close