# Eaton Works Feed

Feed of news/blog postings on the Eaton Works website.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Tata's B2B platform returned OTPs in API responses

DevFeed: [Tata's B2B platform returned OTPs in API responses](<https://devfeed.tech/articles/tata-s-b2b-platform-returned-otps-in-api-responses-32624.md>)

Original publisher: [Read original article](<https://eaton-works.com/2026/08/24/tata-nexarc-hack/>)

Author: Eaton

Published: 2026-08-24T14:25:14Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [account takeover](<https://devfeed.tech/topics/account-takeover.md>), [API](<https://devfeed.tech/topics/api.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Binance](<https://devfeed.tech/topics/binance.md>)

Tags: [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [api](<https://devfeed.tech/tags/api.md>), [b2b](<https://devfeed.tech/tags/b2b.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [platform](<https://devfeed.tech/tags/platform.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

A security write-up describes a vulnerability in Tata nexarc that returned OTPs in API responses. Because the responses could be decrypted client-side, an attacker with a target's phone number could obtain the OTP and take over the account, including accounts with administrative privileges.

### Source excerpt

Tata's nexarc platform had a vulnerability where OTPs could be decrypted from API responses, making it easy to take over any account.

## Exploiting Volvo/Eicher's fleet management platform to gain control over all users and vehicles

DevFeed: [Exploiting Volvo/Eicher's fleet management platform to gain control over all users and vehicles](<https://devfeed.tech/articles/exploiting-volvo-eicher-s-fleet-management-platform-to-gain-control-over-all-users-and-vehicles-32623.md>)

Original publisher: [Read original article](<https://eaton-works.com/2026/07/27/my-eicher-hack/>)

Author: Eaton

Published: 2026-07-27T14:31:47Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [account takeover](<https://devfeed.tech/topics/account-takeover.md>), [API](<https://devfeed.tech/topics/api.md>), [Security](<https://devfeed.tech/topics/security.md>), [data](<https://devfeed.tech/topics/data.md>), [App](<https://devfeed.tech/topics/app.md>), [Website](<https://devfeed.tech/topics/website.md>), [Android](<https://devfeed.tech/topics/android.md>), [iphone](<https://devfeed.tech/topics/iphone.md>)

Tags: [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [android](<https://devfeed.tech/tags/android.md>), [api](<https://devfeed.tech/tags/api.md>), [app](<https://devfeed.tech/tags/app.md>), [automotive](<https://devfeed.tech/tags/automotive.md>), [data](<https://devfeed.tech/tags/data.md>), [india](<https://devfeed.tech/tags/india.md>), [iphone](<https://devfeed.tech/tags/iphone.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article reports vulnerabilities in VE Commercial Vehicles' My Eicher fleet-management platform that exposed hidden unauthenticated APIs and could enable account takeover and control of users' vehicle fleets. It also describes potentially exposed customer, user, vehicle, and identity-document data. A July 28, 2026 update says the concerns were remediated in coordination with the VECV team and that there was no current threat to customers or vehicles.

### Source excerpt

VE Commercial Vehicles' My Eicher platform had a critical vulnerability that let you take over anyone's account and gain control over their vehicle fleets.

## Inside an AI coal mine security camera network powered by plaintext passwords

DevFeed: [Inside an AI coal mine security camera network powered by plaintext passwords](<https://devfeed.tech/articles/inside-an-ai-coal-mine-security-camera-network-powered-by-plaintext-passwords-32622.md>)

Original publisher: [Read original article](<https://eaton-works.com/2026/07/08/coal-india-camera-hack/>)

Author: Eaton

Published: 2026-07-08T17:07:38Z

Content type: opinion

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [API](<https://devfeed.tech/topics/api.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [breach](<https://devfeed.tech/tags/breach.md>), [browser](<https://devfeed.tech/tags/browser.md>), [chrome](<https://devfeed.tech/tags/chrome.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This security write-up examines Coal India's Project DigiCoal camera-monitoring platform, developed by DeepSight AI Labs and Accenture. It reports that the RPI Dashboard exposed user accounts and plaintext, weak, duplicated passwords through an unauthenticated API. The article also describes bypassing client-side access controls to view camera alerts and feeds across seven coal mines.

### Source excerpt

Coal India's intelligent CCTV platform developed by DeepSight AI Labs and Accenture had plaintext passwords and no API authentication.

## Exploiting vulnerabilities in Johnson & Johnson web apps

DevFeed: [Exploiting vulnerabilities in Johnson & Johnson web apps](<https://devfeed.tech/articles/exploiting-vulnerabilities-in-johnson-johnson-web-apps-32621.md>)

Original publisher: [Read original article](<https://eaton-works.com/2026/06/24/jnj-webapp-hacks/>)

Author: Eaton

Published: 2026-06-24T16:11:49Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [Web](<https://devfeed.tech/topics/web.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [data](<https://devfeed.tech/topics/data.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [apis](<https://devfeed.tech/tags/apis.md>), [audit](<https://devfeed.tech/tags/audit.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [aws](<https://devfeed.tech/tags/aws.md>), [data](<https://devfeed.tech/tags/data.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [web](<https://devfeed.tech/tags/web.md>), [web-apps](<https://devfeed.tech/tags/web-apps.md>)

### AI overview

The article reports vulnerabilities in two Johnson & Johnson web applications. A campus recruiting application exposed student information because its APIs used a hardcoded AWS API key instead of the Microsoft SSO token. The article also reports a vulnerability in the Audit Tracking Management System involving confidential internal audit data.

### Source excerpt

Campus Recruiting vulnerability exposed student information, and Audit Tracking Management System vulnerability exposed confidential internal audit data.

## Using cookies to hack into a tech college's admission system

DevFeed: [Using cookies to hack into a tech college's admission system](<https://devfeed.tech/articles/using-cookies-to-hack-into-a-tech-college-s-admission-system-32620.md>)

Original publisher: [Read original article](<https://eaton-works.com/2026/03/09/skcet-hack/>)

Author: Eaton

Published: 2026-03-09T13:41:25Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Web app](<https://devfeed.tech/topics/webapp.md>), [API](<https://devfeed.tech/topics/api.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [HTTP](<https://devfeed.tech/topics/http.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [cookies](<https://devfeed.tech/tags/cookies.md>), [data](<https://devfeed.tech/tags/data.md>), [http](<https://devfeed.tech/tags/http.md>), [india](<https://devfeed.tech/tags/india.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [web](<https://devfeed.tech/tags/web.md>), [web-app](<https://devfeed.tech/tags/web-app.md>)

### AI overview

The article describes how missing authentication on SKCET's admission APIs allowed manual cookie manipulation to bypass login and impersonate an admission officer. By discovering an officer GUID through student searches, the author accessed reports containing sensitive information about 4,110 students, including contact, address, Aadhaar, medical, demographic, academic, and income data.

### Source excerpt

The Sri Krishna College of Engineering and Technology (SKCET) in India made elementary mistakes in web app security.

## Insecure Dava India Pharmacy APIs Exposed Super Admin Users and Enabled Privileged Account Creation

DevFeed: [Insecure Dava India Pharmacy APIs Exposed Super Admin Users and Enabled Privileged Account Creation](<https://devfeed.tech/articles/hacking-a-pharmacy-to-get-free-prescription-drugs-and-more-32619.md>)

Original publisher: [Read original article](<https://eaton-works.com/2026/02/13/dava-india-hack/>)

Author: Eaton

Published: 2026-02-14T03:07:20Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Website](<https://devfeed.tech/topics/website.md>), [account](<https://devfeed.tech/topics/account.md>), [password reset](<https://devfeed.tech/topics/password-reset.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Next.js](<https://devfeed.tech/topics/next-js.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [password](<https://devfeed.tech/tags/password.md>), [website](<https://devfeed.tech/tags/website.md>)

### AI overview

A security write-up describes insecure super-admin APIs on Dava India Pharmacy's website. The APIs exposed a list of super-admin users without authentication, and testing indicated that creating a super-admin account was a supported operation.

### Source excerpt

Super admin exploit on Dava India Pharmacy's website gave complete control over everything.

## Security vulnerabilities in Bluspark Global's BLUVOYIX ocean logistics platform

DevFeed: [Security vulnerabilities in Bluspark Global's BLUVOYIX ocean logistics platform](<https://devfeed.tech/articles/i-m-the-captain-now-hijacking-a-global-ocean-supply-chain-network-32618.md>)

Original publisher: [Read original article](<https://eaton-works.com/2026/01/14/bluspark-bluvoyix-hack/>)

Author: Eaton

Published: 2026-01-14T15:05:15Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [API](<https://devfeed.tech/topics/api.md>), [Binance](<https://devfeed.tech/topics/binance.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [code](<https://devfeed.tech/tags/code.md>), [cve](<https://devfeed.tech/tags/cve.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

An investigation into critical security vulnerabilities in Bluspark Global's BLUVOYIX ocean logistics platform, including unauthenticated APIs, exposed API documentation, self-created administrator accounts, phishing-capable email functionality, and plaintext password access. The article states that the issues were resolved by publication and that administrator access could expose and alter customer shipments.

### Source excerpt

Exploring security blunders in Bluspark Global's BLUVOYIX, an ocean logistics / supply chain platform used by hundreds of the world's largest companies.

## Cracker Barrel rewards admin panel vulnerability allowed API requests without an authorization token

DevFeed: [Cracker Barrel rewards admin panel vulnerability allowed API requests without an authorization token](<https://devfeed.tech/articles/a-cracker-barrel-vulnerability-32617.md>)

Original publisher: [Read original article](<https://eaton-works.com/2025/11/17/cracker-barrel-hack/>)

Author: Eaton

Published: 2025-11-17T15:31:02Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [api server](<https://devfeed.tech/topics/api-server.md>), [React](<https://devfeed.tech/topics/react.md>)

Tags: [admin](<https://devfeed.tech/tags/admin.md>), [api](<https://devfeed.tech/tags/api.md>), [api-server](<https://devfeed.tech/tags/api-server.md>), [auth](<https://devfeed.tech/tags/auth.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [bypass](<https://devfeed.tech/tags/bypass.md>), [panel](<https://devfeed.tech/tags/panel.md>), [react](<https://devfeed.tech/tags/react.md>), [third-party](<https://devfeed.tech/tags/third-party.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article describes a vulnerability in Cracker Barrel's rewards administration system. The author found that the React app's API server accepted requests without an authorization token, potentially allowing access to rewards management functions. No write actions were performed, no sensitive information was exposed, and the vulnerability appeared to be fixed by November 17, 2025.

### Source excerpt

Cracking open the rewards admin panel.

## Hacking India's largest automaker: Tata Motors

DevFeed: [Hacking India's largest automaker: Tata Motors](<https://devfeed.tech/articles/hacking-india-s-largest-automaker-tata-motors-32616.md>)

Original publisher: [Read original article](<https://eaton-works.com/2025/10/28/tata-motors-hack/>)

Author: Eaton

Published: 2025-10-29T01:05:40Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Hacking](<https://devfeed.tech/topics/hacking.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Amazon S3](<https://devfeed.tech/topics/amazon-s3.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [data](<https://devfeed.tech/topics/data.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>)

Tags: [amazon](<https://devfeed.tech/tags/amazon.md>), [aws](<https://devfeed.tech/tags/aws.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [database](<https://devfeed.tech/tags/database.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [india](<https://devfeed.tech/tags/india.md>), [s3](<https://devfeed.tech/tags/s3.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article describes four security findings involving Tata Motors discovered in 2023. It reports that exposed AWS keys on public-facing websites enabled access to sensitive information across many S3 buckets, that weakly encrypted keys could be decrypted, that a Tableau backdoor allowed passwordless login as users including an administrator, and that an exposed Azuga API key compromised a test-drive fleet management system. The author states that the disclosed credentials were rotated and that testing did not download substantial amounts of data or show obvious evidence of malicious access.

### Source excerpt

Tata Motors gave away the keys to their infrastructure and customer data on their public websites.

## Vulnerabilities in a centralized automaker dealer platform enabled access to more than 1,000 US dealerships

DevFeed: [Vulnerabilities in a centralized automaker dealer platform enabled access to more than 1,000 US dealerships](<https://devfeed.tech/articles/def-con-33-how-i-hacked-over-1-000-car-dealerships-across-the-us-32615.md>)

Original publisher: [Read original article](<https://eaton-works.com/2025/10/13/def-con-33/>)

Author: Eaton

Published: 2025-10-13T15:13:09Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [account](<https://devfeed.tech/topics/account.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [automotive-industry](<https://devfeed.tech/tags/automotive-industry.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [us](<https://devfeed.tech/tags/us.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article describes two vulnerabilities in a top automaker's centralized dealer platform: missing invite-token verification and a missing privilege check in account creation. The author states that these flaws enabled creation of a national admin account with access to systems across more than 1,000 US dealerships.

### Source excerpt

On August 10, 2025 at DEF CON 33 in Las Vegas, I presented what could possibly be the biggest vulnerability I may ever discover in the automotive industry. Read and watch how I managed to take over a top automaker's entire dealer ecosystem.

## Taking remote control over industrial generators

DevFeed: [Taking remote control over industrial generators](<https://devfeed.tech/articles/taking-remote-control-over-industrial-generators-32614.md>)

Original publisher: [Read original article](<https://eaton-works.com/2025/10/06/industrial-generator-hack/>)

Author: Eaton

Published: 2025-10-06T15:13:20Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [generators](<https://devfeed.tech/topics/generators.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>), [API](<https://devfeed.tech/topics/api.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [api-security](<https://devfeed.tech/tags/api-security.md>), [apis](<https://devfeed.tech/tags/apis.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [industrial](<https://devfeed.tech/tags/industrial.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

An industrial generator management platform had insecure APIs that accepted valid user tokens without checking whether the user had administrator privileges. This broken function-level authorization could expose generator data and commands to start or stop generators. The commands were not tested because doing so could have created a safety hazard.

### Source excerpt

Industrial generator smart platform had insecure APIs that could enable remote control by anyone.

## Intel Outside: Hacking every Intel employee and various internal websites

DevFeed: [Intel Outside: Hacking every Intel employee and various internal websites](<https://devfeed.tech/articles/intel-outside-hacking-every-intel-employee-and-various-internal-websites-32613.md>)

Original publisher: [Read original article](<https://eaton-works.com/2025/08/18/intel-outside-hack/>)

Author: Eaton

Published: 2025-08-18T14:15:43Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Hacking](<https://devfeed.tech/topics/hacking.md>), [intel](<https://devfeed.tech/topics/intel.md>), [hardcoded credentials](<https://devfeed.tech/topics/hardcoded-credentials.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Angular](<https://devfeed.tech/topics/angular.md>), [Azure](<https://devfeed.tech/topics/azure.md>)

Tags: [angular](<https://devfeed.tech/tags/angular.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [azure](<https://devfeed.tech/tags/azure.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [hardcoded-credentials](<https://devfeed.tech/tags/hardcoded-credentials.md>), [intel](<https://devfeed.tech/tags/intel.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>)

### AI overview

This security investigation describes vulnerabilities in several internal Intel websites. The issues included bypassing corporate login controls, exploiting easily decryptable hardcoded credentials, and using client-side modifications to access employee and supplier information.

### Source excerpt

Hardcoded credentials, pointless encryption, and generous APIs exposed details of every employee and made it possible to break into internal websites.

## API flaws in McDelivery India enabled discounted orders, order hijacking, and access to user information

DevFeed: [API flaws in McDelivery India enabled discounted orders, order hijacking, and access to user information](<https://devfeed.tech/articles/i-m-lovin-it-exploiting-mcdonald-s-apis-to-hijack-deliveries-and-order-food-for-a-penny-32612.md>)

Original publisher: [Read original article](<https://eaton-works.com/2024/12/19/mcdelivery-india-hack/>)

Author: Eaton

Published: 2024-12-19T13:00:22Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [API](<https://devfeed.tech/topics/api.md>), [Security](<https://devfeed.tech/topics/security.md>), [Web app](<https://devfeed.tech/topics/webapp.md>), [Website](<https://devfeed.tech/topics/website.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [bug](<https://devfeed.tech/tags/bug.md>), [security](<https://devfeed.tech/tags/security.md>), [service](<https://devfeed.tech/tags/service.md>), [user](<https://devfeed.tech/tags/user.md>), [web-app](<https://devfeed.tech/tags/web-app.md>)

### AI overview

A security disclosure describes API flaws in McDelivery India that enabled orders for INR 1, hijacking or redirecting other customers' deliveries, access to order details and invoices, order tracking, and exposure of sensitive driver information.

### Source excerpt

A series of API flaws in McDelivery India made it possible to order food for a penny, hijack other people's delivery orders, view user information, and more.

## Honeywell BEDQ API Access Control Flaw Exposed an Internal Engineering System

DevFeed: [Honeywell BEDQ API Access Control Flaw Exposed an Internal Engineering System](<https://devfeed.tech/articles/how-1-exposed-honeywell-api-gave-me-control-over-an-internal-engineering-system-32611.md>)

Original publisher: [Read original article](<https://eaton-works.com/2024/08/19/honeywell-bedq-hack/>)

Author: Eaton

Published: 2024-08-19T04:00:00Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [API](<https://devfeed.tech/topics/api.md>), [Security](<https://devfeed.tech/topics/security.md>), [Access Control](<https://devfeed.tech/topics/access-control.md>), [Angular](<https://devfeed.tech/topics/angular.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [access-control](<https://devfeed.tech/tags/access-control.md>), [angular](<https://devfeed.tech/tags/angular.md>), [api](<https://devfeed.tech/tags/api.md>), [api-security](<https://devfeed.tech/tags/api-security.md>), [security](<https://devfeed.tech/tags/security.md>), [web-apps](<https://devfeed.tech/tags/web-apps.md>)

### AI overview

The article describes how an insecure API endpoint in Honeywell's BEDQ system exposed an internal engineering application. It examines weaknesses in access control between internal users and externally registered Honeywell IDs, and emphasizes the need for stronger API security.

### Source excerpt

(ASPEN) APIs are crucial for web apps but pose security risks. I uncovered a critical flaw in Honeywell's BEDQ system, highlighting the need for strong API security.

## Gaining admin access to a Siemens cloud system

DevFeed: [Gaining admin access to a Siemens cloud system](<https://devfeed.tech/articles/gaining-admin-access-to-a-siemens-cloud-system-32610.md>)

Original publisher: [Read original article](<https://eaton-works.com/2024/07/31/siemens-ama-hack/>)

Author: Eaton

Published: 2024-07-31T04:00:00Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Entra ID](<https://devfeed.tech/topics/entra-id.md>), [React](<https://devfeed.tech/topics/react.md>), [Angular](<https://devfeed.tech/topics/angular.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [Single-page application (SPA)](<https://devfeed.tech/topics/spa.md>), [API](<https://devfeed.tech/topics/api.md>), [JSON Web Tokens](<https://devfeed.tech/topics/jwt.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>)

Tags: [angular](<https://devfeed.tech/tags/angular.md>), [api](<https://devfeed.tech/tags/api.md>), [api-discovery](<https://devfeed.tech/tags/api-discovery.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [jwt](<https://devfeed.tech/tags/jwt.md>), [react](<https://devfeed.tech/tags/react.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article examines a vulnerability in Siemens AMA Cloud, a React-based cloud application. It explains how insufficient server-side authentication and reliance on client-side controls can expose APIs and allow manipulation of the application's authentication flow, including its Microsoft SSO redirect and JWT handling.

### Source excerpt

(ASPEN) Understanding the Risks of Client-Side Authentication: Why relying on client-side security isn't enough.

## Lessons in Securing Mobility Site Management APIs

DevFeed: [Lessons in Securing Mobility Site Management APIs](<https://devfeed.tech/articles/lessons-in-securing-mobility-site-management-apis-32609.md>)

Original publisher: [Read original article](<https://eaton-works.com/2024/05/16/jnj-mobility-hack/>)

Author: Eaton

Published: 2024-05-16T04:00:00Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Mobile](<https://devfeed.tech/topics/mobile.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [API](<https://devfeed.tech/topics/api.md>), [Security](<https://devfeed.tech/topics/security.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [PHP](<https://devfeed.tech/topics/php.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>)

Tags: [apis](<https://devfeed.tech/tags/apis.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [network](<https://devfeed.tech/tags/network.md>), [php](<https://devfeed.tech/tags/php.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This article examines vulnerabilities in the PHP APIs behind Johnson & Johnson's Mobility Service Portal. Researchers reported that the vulnerabilities allowed access to details about employee corporate devices, and Johnson & Johnson remediated the issue after receiving the report.

### Source excerpt

(ASPEN) Mobile device management (MDM) systems are essential for large enterprises to track devices accessing the corporate network and ensure security. Read how a vulnerability on Johnson & Johnson's Mobility Service Portal made it possible to access employee corporate devices.

## Angular-ing for AuthZ, Problematic anti-patterns in Single Sign On Systems

DevFeed: [Angular-ing for AuthZ, Problematic anti-patterns in Single Sign On Systems](<https://devfeed.tech/articles/angular-ing-for-authz-problematic-anti-patterns-in-single-sign-on-systems-32608.md>)

Original publisher: [Read original article](<https://eaton-works.com/2024/03/05/f500-app-hack/>)

Author: Eaton

Published: 2024-03-05T05:00:00Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Single sign-on (SSO)](<https://devfeed.tech/topics/sso.md>), [authz](<https://devfeed.tech/topics/authz.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Angular](<https://devfeed.tech/topics/angular.md>), [API keys](<https://devfeed.tech/topics/api-keys.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [angular](<https://devfeed.tech/tags/angular.md>), [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authz](<https://devfeed.tech/tags/authz.md>), [security](<https://devfeed.tech/tags/security.md>), [sso](<https://devfeed.tech/tags/sso.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article describes an ASPEN team's research into an SSO login-flow flaw in an Angular application at a Fortune 500 healthcare company. It explains that exposed client-side API credentials and a user-search API accepting the value "all" enabled retrieval of user information; the reported vulnerability was resolved and mitigated.

### Source excerpt

(ASPEN) A critical SSO vulnerability in a Fortune 500 app risked millions of records. Learn about SSO security risks, fixes, and protecting APIs from similar attacks.

## Hacking into a Toyota/Eicher Motors insurance company by exploiting their premium calculator website

DevFeed: [Hacking into a Toyota/Eicher Motors insurance company by exploiting their premium calculator website](<https://devfeed.tech/articles/hacking-into-a-toyota-eicher-motors-insurance-company-by-exploiting-their-premium-calculator-website-32607.md>)

Original publisher: [Read original article](<https://eaton-works.com/2024/01/17/ttibi-email-hack/>)

Author: Eaton

Published: 2024-01-17T16:25:39Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Hacking](<https://devfeed.tech/topics/hacking.md>), [API](<https://devfeed.tech/topics/api.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Website](<https://devfeed.tech/topics/website.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [broker](<https://devfeed.tech/tags/broker.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [india](<https://devfeed.tech/tags/india.md>), [insurance](<https://devfeed.tech/tags/insurance.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [password](<https://devfeed.tech/tags/password.md>)

### AI overview

A security report describes how a vulnerable API on Toyota Tsusho Insurance Broker India's premium calculator website exposed Microsoft corporate cloud credentials. The exposed account lacked two-factor authentication and contained customer emails, insurance documents, password reset links, and OTPs. Other Microsoft cloud resources were also accessible.

### Source excerpt

A vulnerable API on Toyota Tsusho Insurance Broker India's premium calculator website exposed Microsoft corporate cloud credentials.

## CVE-2023-6483: Improper/missing API authentication in ADiTaaS v5.1

DevFeed: [CVE-2023-6483: Improper/missing API authentication in ADiTaaS v5.1](<https://devfeed.tech/articles/cve-2023-6483-improper-missing-api-authentication-in-aditaas-v5-1-32606.md>)

Original publisher: [Read original article](<https://eaton-works.com/2023/12/18/aditaas-cve-2023-6483/>)

Author: Eaton

Published: 2023-12-18T15:52:29Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [API](<https://devfeed.tech/topics/api.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Angular](<https://devfeed.tech/topics/angular.md>), [.NET](<https://devfeed.tech/topics/net.md>)

Tags: [angular](<https://devfeed.tech/tags/angular.md>), [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [backend](<https://devfeed.tech/tags/backend.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [digital](<https://devfeed.tech/tags/digital.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [on-prem](<https://devfeed.tech/tags/on-prem.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article examines CVE-2023-6483, a critical API authentication flaw in ADiTaaS v5.1, now Digital Desk. The vulnerability allowed system administrator access by using an administrator user ID in the URL. The article describes responsible disclosure, remediation completed by December 1, 2023, and the range of organizations that could have been affected.

### Source excerpt

The story of CVE-2023-6483, my first CVE and biggest security disclosure yet.

## Tapping into a telecommunications company's office cameras

DevFeed: [Tapping into a telecommunications company's office cameras](<https://devfeed.tech/articles/tapping-into-a-telecommunications-company-s-office-cameras-32605.md>)

Original publisher: [Read original article](<https://eaton-works.com/2023/11/14/telecom-camera-hack/>)

Author: Eaton

Published: 2023-11-14T18:53:08Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [API](<https://devfeed.tech/topics/api.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [React](<https://devfeed.tech/topics/react.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [JSON](<https://devfeed.tech/topics/json.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [incident](<https://devfeed.tech/tags/incident.md>), [json](<https://devfeed.tech/tags/json.md>), [react](<https://devfeed.tech/tags/react.md>), [reporting](<https://devfeed.tech/tags/reporting.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

An unauthenticated API endpoint in a telecommunications company's office camera platform exposed a live image stream. The article describes how the endpoint was found, the read-only privacy impact, and the company's incident-reporting timeline.

### Source excerpt

API flaw enabled livestreaming of a telecommunications company's office cameras.

## Compromising Honda's power equipment / marine / lawn & garden dealer eCommerce platform through a vulnerable password reset API

DevFeed: [Compromising Honda's power equipment / marine / lawn & garden dealer eCommerce platform through a vulnerable password reset API](<https://devfeed.tech/articles/compromising-honda-s-power-equipment-marine-lawn-garden-dealer-ecommerce-platform-through-a-vulnerable-password-reset-api-32604.md>)

Original publisher: [Read original article](<https://eaton-works.com/2023/06/06/honda-ecommerce-hack/>)

Author: Eaton

Published: 2023-06-06T15:33:57Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [API](<https://devfeed.tech/topics/api.md>), [password reset](<https://devfeed.tech/topics/password-reset.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Website](<https://devfeed.tech/topics/website.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [data](<https://devfeed.tech/tags/data.md>), [ecommerce](<https://devfeed.tech/tags/ecommerce.md>), [password-reset](<https://devfeed.tech/tags/password-reset.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [website](<https://devfeed.tech/tags/website.md>)

### AI overview

A writeup describes compromising Honda's power equipment, marine, and lawn-and-garden dealer eCommerce platform through a vulnerable password reset API and broken access controls. The reported access included customer orders, dealer websites and accounts, email records, and potentially payment-related keys and internal financial reports. The incident did not affect Honda's automobile business.

### Source excerpt

A vulnerable password reset API made it possible to take over any account and gain admin-level access to the platform. In addition, broken/missing access controls made it possible to access all data on the platform.

## Insecure Toyota CRM exposed Mexican customer information

DevFeed: [Insecure Toyota CRM exposed Mexican customer information](<https://devfeed.tech/articles/insecure-toyota-crm-exposed-mexican-customer-information-32603.md>)

Original publisher: [Read original article](<https://eaton-works.com/2023/03/06/toyota-c360-hack/>)

Author: Eaton

Published: 2023-03-06T17:52:27Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Web app](<https://devfeed.tech/topics/webapp.md>), [Angular](<https://devfeed.tech/topics/angular.md>), [API](<https://devfeed.tech/topics/api.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [data](<https://devfeed.tech/topics/data.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [angular](<https://devfeed.tech/tags/angular.md>), [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [data](<https://devfeed.tech/tags/data.md>), [security](<https://devfeed.tech/tags/security.md>), [web-app](<https://devfeed.tech/tags/web-app.md>)

### AI overview

A security writeup describes how Toyota's C360 CRM for Mexican customers could be accessed by bypassing its corporate login and switching a development app to the production API. The exposed unauthenticated API returned customer information, and Toyota fixed the issue after responsible disclosure.

### Source excerpt

Breaking into a Toyota CRM and exploiting it to view customer information.

## Hacking into Toyota's global supplier management network

DevFeed: [Hacking into Toyota's global supplier management network](<https://devfeed.tech/articles/hacking-into-toyota-s-global-supplier-management-network-32602.md>)

Original publisher: [Read original article](<https://eaton-works.com/2023/02/06/toyota-gspims-hack/>)

Author: Eaton

Published: 2023-02-06T16:22:56Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Web app](<https://devfeed.tech/topics/webapp.md>), [account](<https://devfeed.tech/topics/account.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [data](<https://devfeed.tech/tags/data.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [web-app](<https://devfeed.tech/tags/web-app.md>)

### AI overview

A security researcher describes exploiting Toyota's Global Supplier Preparation Information Management System (GSPIMS), a web application used by Toyota employees and suppliers. An accidentally introduced backdoor in an impersonation feature enabled login as users, including administrators, using only their email addresses. The researcher reported the issue to Toyota in November 2022, and Toyota fixed it in a timely manner.

### Source excerpt

Inside an exploit that allowed logging in to Toyota's GSPIMS application as any user, including system admins.

## Syndication feed now available

DevFeed: [Syndication feed now available](<https://devfeed.tech/articles/syndication-feed-now-available-32601.md>)

Original publisher: [Read original article](<https://eaton-works.com/2023/01/28/syndication-feed-now-available/>)

Author: Eaton

Published: 2023-01-28T17:38:46Z

Content type: release

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Atom Feed](<https://devfeed.tech/topics/atom-feed.md>), [Atom](<https://devfeed.tech/topics/atom.md>), [RSS](<https://devfeed.tech/topics/rss.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [rss](<https://devfeed.tech/tags/rss.md>), [syndication](<https://devfeed.tech/tags/syndication.md>)

### AI overview

The site now provides an Atom syndication feed. New posts will be added automatically when published, and the feed is intended to work with compatible readers.

### Source excerpt

An Atom feed is now available for the site.

[Next page](<https://devfeed.tech/sources/eaton-works-feed.md?cursor=WyIyMDIzLTAxLTI4VDE3OjM4OjQ2KzAwOjAwIiwgImJiZGVlMzFmLWRjMmMtNDY2Ny04NzM3LWU0MWYxYzcwYjViNyJd>)