Connect with us

Tech

Klaviyo Sign-Up Bug May Have Exposed Passwords to Ad Trackers

Published

on

Klaviyo has fixed a website configuration bug that may have exposed new customers’ sign-up data, including passwords, to third-party trackers embedded on its site.

The company says fewer than 200 people are known to have been affected based on its readily available active logs. That figure is not a final total, because Klaviyo has not said how far back those logs extend or exactly how long the misconfiguration remained live.

What the Klaviyo sign-up bug may have exposed

TechCrunch reported that security researcher Sam Jadali, co-founder of Melurna, found the Klaviyo sign-up form was misconfigured from at least February 2024 through November 2025 and possibly longer. Melurna’s testing found that sign-up data may have been shared with trackers operated by companies including Meta, Google, HubSpot, Microsoft, LinkedIn, and X.

The information reportedly included email addresses, passwords, company names, website addresses, and phone numbers. The reporting describes a browser-side data exposure involving trackers, not evidence that attackers breached Klaviyo’s customer database.

Klaviyo attributed the bug to an “application configuration issue” and said it notified the people it identified as affected. The company did not tell TechCrunch how far back its active logs go, meaning the fewer-than-200 figure cannot be treated as the total number affected across the full period identified by Melurna.

The reporting concerns Klaviyo’s own account-registration form, rather than consumer sign-up forms run by retailers using the platform. For businesses whose credentials may have been exposed, the immediate concern is account takeover, particularly when a password was reused or MFA was not enabled.

What Klaviyo customers and IT teams should do now

Anyone who created a Klaviyo account during the reported window should change the password. If the same credential was used elsewhere, reset those accounts too because password reuse can enable credential-stuffing attacks.

Teams should use a password manager to generate unique credentials and review whether MFA is enabled. Klaviyo’s account-security guidance recommends both unique passwords and MFA.

Organizations should also review third-party scripts on registration and login pages and verify that sensitive fields are excluded from analytics and advertising data flows.

Klaviyo’s Activity Log gives administrators a searchable record of edits and other account changes, but it covers activity inside an account rather than data sent from the public registration page.

Until Klaviyo discloses its log-retention window or a complete incident timeline, fewer than 200 people are currently known to be affected while the full scope remains unresolved.

Also read: Fake The Odyssey downloads are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information.

>

Continue Reading

Tech

OpenAI reportedly completed a $7 billion employee tender offer

Published

on

OpenAI has bought back $7 billion worth of shares from employees at the privately held frontier AI lab as part of an effort to provide liquidity to its workforce.

The deal, reported by Bloomberg, valued OpenAI at $852 billion, the same as its most recent fundraising round in March, which added $122 billion to the company’s war chest.

The company also filed confidentially with the Securities and Exchange Commission in June to prepare for a potential IPO later this year. However, a tender offer suggests that an IPO may not be forthcoming soon. With many tech companies remaining private longer than previous generations of startups, private tenders have proven a useful way for firms to allow employees to realize the value of their stock compensation without the difficulties that come with a public offering.

OpenAI did not respond to a request for comment by publication time.

Last month, OpenAI CEO Sam Altman wrote that “we did not have our best 12 months ever, which is mostly my fault, but we are about to have our best 12 months to date.” Firms going public typically want to show strong financial results to bring investors on board, and the Wall Street Journal reported in April that the company missed internal financial goals.

While OpenAI’s incredible growth and products are likely to generate massive interest in public markets, the potential debut of rival Anthropic — which was reportedly profitable earlier this year — gives the company a reason to ensure it puts its best face forward. The tender could be another signal that the much-anticipated offering will wait for OpenAI’s new strategy of paring down its bets and focusing on its enterprise business to gain traction.

>

Continue Reading

Tech

As AI-led attacks multiply, OpenAI launches a new cyber model

Published

on

Every day seems to brings fresh news of an AI agent going “rogue.” Whether that’s compromising Hugging Face, hacking a gym website, or creating its own fake profiles to socially engineer an intrusion, AI models are increasingly behaving like bad actors.

So, the AI labs that make the models doing the hacking are expanding their cyber protection offerings. This week, OpenAI announced an expansion of Daybreak, its cyber defense service which it launched earlier this year, not long after Anthropic released its cyber-focused model Mythos.

Daybreak is a service that bundles access to models, tools and workflows for defenders. The expansion includes access to a brand new cyber-focused model designed for defensive work.

OpenAI said Monday that Daybreak would now consist of two tiers: Blue and Red. Both of these tiers will allow approved customers access to OpenAI’s limited-access frontier cyber models. Frontier models — the most advanced available — have been a subject of controversy. The Trump administration previously sought to collaborate with AI companies on the roll out of such models, purportedly over safety concerns. Previously, OpenAI deployed significant guardrails to using these models, limiting what customers could do with them.

Blue, which appears to be the more basic of the two, offers a variety of cyber services, including incident response, malware analysis, and patch validation. OpenAI calls Blue its “recommended starting point for most defenders,” implying that it should be more than enough for most enterprises.

Red, on the other hand, offers a broader and potentially more dangerous toolkit. The company grants its users “purpose-trained cybersecurity models,” designed to carry out security testing and vulnerability research.

With Red also comes the new model, GPT‑5.6‑Cyber, which is only available at that tier. 5.6-Cyber is built off of GPT‑5.6 Sol, and offers enhanced capabilities for certain specialized cybersecurity tasks, the company said.

At the moment, GPT‑5.6‑Cyber is only being made available for “trusted customer partners,” including reportedly Accenture, IBM, Crowdstrike, Cloudflare, and others.

While the threats from AI agents are rapidly increasing, critics have also pointed out that they function as marketing opportunities for the AI labs. OpenAI is certainly marketing its upgraded Daybreak that way.

“The cybersecurity world is rapidly changing—threat actors will increasingly use AI to conduct cyberattacks at unprecedented speed and scale, including in fully autonomous ways,” the company said in a blog post. “As these capabilities spread, defenders have a narrowing window to prepare.” 

At the same time, enterprises remain interested in buying their protection from the AI labs who know the security risks best, because they know them first-hand.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

Jeff Bezos might finally get his hands on a sports team

Published

on

Jeff Bezos is reportedly attempting to join the club of very rich Americans buying stakes in U.K. soccer teams.

Bezos, alongside others including Facebook co-founder Eduardo Saverin, is looking to buy at least a 30% stake in the English soccer team Liverpool at a £1.35 billion valuation (around $1.8 billion), the Guardian reports. If the deal closes, it will be the first sports investment for the billionaire, although he reportedly previously looked at buying a stake in a US football team.

Liverpool is one of the most notable sports teams in Europe and is worth about $6 billion, reports Forbes. Arguably, this team has the kind of brand recognition in the U.K. as the Dallas Cowboys has in the U.S.

It seems no billionaire portfolio is complete these days without a mega yacht and a sports team, so Bezos’ interest is not surprising. There’s also something very romantic these days about owning an English soccer team after the success of TV shows like Ted Lasso and Ryan Reynolds’ FX show Welcome to Wrexham about his experience owning that English team. 

Other American billionaires in this club include Todd Boehly and Mark Walters (who also own the LA Dodgers and LA Lakers) buying Chelsea; New York Jets co-owner (and former U.S. Ambassador to the U.K.) Woody Johnson buying Crystal Palace; Dan Friedkin taking a stake in Everton; and Bill Foley leading a group that also included Michael B. Jordan buying Bournemouth.

For that matter, owning a stake in a U.K. sports team has also become a celebrity cultural phenom. Besides Reynolds and Jordan, Tom Brady purchased a minority stake in Birmingham City. Will Ferrell has a minority stake in Leeds United, alongside Russell Westbrook and Michael Phelps.

Liverpool is one of the top names in English football Image Credits:Chris Brunskill/Fantasista / Contributor / Getty Images

Sky Sports had a story earlier this year mapping out why so many Americans seem to be taking over U.K. football. It found that 13 out of 20 Premier League clubs (the top football league in England) had American shareholders.

Soccer has become increasingly popular in the U.S., and many of the top sports franchises, like the NFL and MLB, are either too expensive or closed off to new buyers. It’s much more possible to buy into a Premier League team.

Owning a share in such a team also buys access and proximity to some of the most bankable and recognizable sports icons on Earth. Bezos over the past few years — especially since he married former news anchor and TV show host Lauren Sanchez — has become seen as more of a cultural figure, rather than solely a tech mogul.

So, with a net worth currently sitting at around $280 billion, perhaps it’s actually more than time that Bezos got himself a sports team. Amazon has also streamed some European soccer leagues in the past — and Bezos has growing interests in the U.K. As we previously reported, his new AI company Prometheus is reportedly looking to sign a lease to move into London’s AI hub King’s Cross.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.