Уровень 0 · материалов: 9
В кластер входят документы о выявлении технических уязвимостей в ИТ-системах и последующих конфликтах или неэффективном взаимодействии между нашедшим ошибку и компанией.
Общие признаки: сообщения об уязвимостях безопасности, критика реакции компаний на отчеты, отказ в выплате вознаграждений, небрежность в кибербезопасности, утечки персональных данных
Группа выше: Bug bounty и раскрытие уязвимостей
Смысл: The text argues that Yandex displayed unacceptable negligence by failing to patch a reported XSS vulnerability in a timely manner, leading to financial loss for users. The main idea is that large tech companies managing financial data must prioritize security reports over template responses to prevent predictable attacks.
The author criticizes Yandex for ignoring an XSS vulnerability report for 20 days, which subsequently allowed attackers to steal money from users' wallets.
Смысл: The main idea is to expose severe security vulnerabilities in Yandex.Taxi's infrastructure that allowed for massive data leaks and business manipulation, while critically questioning why a major company would spend a billion rubles on such insecure software without a technical audit.
A security researcher exposes how a total lack of authorization in Yandex.Taxi's software allowed the theft of driver data and order manipulation, suggesting the billion-ruble acquisition lacked any due diligence.
Смысл: The text highlights a systemic failure in the cybersecurity culture of YooMoney/Sberbank, where a critical vulnerability was ignored for months and the researcher who reported it was denied a reward through deceptive administrative tactics.
A security researcher found a critical data leak in YooMoney but was denied a bug bounty payment after the company falsely claimed the report was a duplicate.
Смысл: The text exposes a security flaw in Yandex Market where lack of email verification allows personal data leaks and potential theft of goods, while criticizing the company's dismissive approach to resolving the issue.
A user reports receiving another customer's order codes and personal data from Yandex Market, highlighting a systemic failure in email verification and data protection.
Смысл: The text illustrates the critical danger of Cross-Site Scripting (XSS) vulnerabilities and the risk associated with administrative negligence when handling security reports.
An author discovers an XSS vulnerability on a website, hijacks several accounts including a developer's due to administrative inaction, and eventually forces a patch by posting a public warning.
Смысл: The main idea is to criticize Kyivstar's inadequate response to critical security vulnerabilities and its insulting reward system, highlighting a dangerous gap between corporate claims of security and actual practice.
A security researcher discovered full administrative access to Kyivstar's core corporate services via a leaked password file but was rewarded with only $50.
Смысл: The text highlights the poor communication and lack of ethics in VK's handling of a security vulnerability report, where the company benefited from a researcher's discovery but refused any compensation based on a technicality.
A security researcher discovered a privacy flaw in VK's API but was denied payment after the company took eight months to fix it and then claimed it didn't fit their new bug bounty criteria.
Смысл: The text describes a conflict between a Ukrainian programmer, Alexey Mokhov, who discovered a critical security flaw in PrivatBank's Android app, and the bank, which responded by accusing him of attempting theft instead of thanking him for the discovery.
A programmer who found and reported a critical security flaw in PrivatBank's Android app was accused by the bank of attempting to steal funds.
Смысл: The main idea is to satirize Sberbank's decision to crowdsource the debugging of a critical system failure because their own staff could not find the cause, notably without offering payment.
Sberbank admitted its experts couldn't fix a processing outage and asked unpaid volunteers to analyze system logs to find the cause.