Categories: Tech & Ai

Naukri exposed recruiter email addresses, researcher says


Naukri.com, a popular Indian employment website, has fixed a bug that exposed the email addresses of recruiters using its platform to search and hire talent online.

The issue, discovered by security researcher Lohith Gowda, affected the API that Naukri used on its Android and iOS apps. The API exposed the email addresses of recruiters visiting profiles of potential candidates on Naukri’s platform. The issue did not appear to affect the company’s website.

“The exposed recruiter email IDs can be used for targeted phishing attacks, and recruiters may receive excessive unsolicited emails and spam,” Gowda told TechCrunch.

He added that exposed email IDs could be added to public breach databases or spam lists, and mass email address scraping could lead to automated bot abuse or scams.

TechCrunch verified the exposure after the researcher shared details about the bug. The researcher confirmed to TechCrunch that the issue was fixed earlier this week, which Naukri corroborated on Friday.

“All identified enhancements are implemented, ensuring our systems remain updated and resilient,” Alok Vij, IT infrastructure head at Naukri’s parent company InfoEdge, told TechCrunch over email. “Our teams have not detected any usual activity that affects the integrity of user data.”

Founded in March 1997, Naukri.com is India’s top classified recruitment website, helping connect recruiters, employers, and job seekers. Apart from India, the site exists in the Middle East as Naukrigulf.com.

“Certain features of our recruiter profiles are designed to be public to enable users to know who has access to their profile(s). We conduct regular audits and security assessments,” said Vij.



Source link

Abigail Avery

Share
Published by
Abigail Avery

Recent Posts

Michael Saylor’s Strategy Nets $14 Billion in Q2, Launches $4.2B Stock Blitz for More BTC

MicroStrategy, now Strategy, just reported a jaw-dropping $14 billion in unrealized gains for Q2 of…

23 minutes ago

I own these Philips Hue Smart Bulbs — this Prime Day deal is too good to ignore

SAVE $55.35: A three-pack of Philips Hue color and white smart bulbs is on sale…

31 minutes ago

Linqto Files Bankruptcy Amid Legal Probes and Corporate Structure Issues

Linqto’s Chapter 11 bankruptcy filing exposes deep structural flaws and regulatory pressure that could upend…

32 minutes ago

Lamborghini and Wilder World Collaborate on New Temerario GT3 and Fast ForWorld Expansion

The emblematic sports car brand, Automobili Lamborghini, announced the first major metaverse expansion of its…

1 hour ago

Grok Is Spewing Antisemitic Garbage on X

Grok’s first reply has since been “deleted by the Post author,” but in subsequent posts…

2 hours ago

Phantom puts perps in traders’ pockets as mobile-first derivatives go live

Perpetual futures see over $100 billion in daily trading volume, yet most platforms still cater…

2 hours ago