10th Indian Delegation to Dubai, Gitex & Expand North Star – World’s Largest Startup Investor Connect
EdTech

Security Researcher Claims Tech Glitch Exposed BYJU’S Students’ Data; Co Denies Leaks

A security researcher has claimed that a technical glitch at BYJU’S exposed sensitive data of students, including their loan and payment details. However, the embattled edtech giant told Inc42 it was a temporary glitch and no data was compromised.

The glitch came to notice after security researcher Bob Diachenko posted on X (formerly Twitter) about it on August 23. “Byju’s, an education technology giant and India’s most valuable startup, exposed data of its customers via misconfigured service instance. While there is no response from the company, personal data of students, incl. loan and payment details along with other info, is at risk,” he said.

TechCrunch reported that names, addresses, phone numbers and email IDs of the students were also exposed.

However, BYJU’S said that no personal data was exposed. “There was a temporary exposure of a small fraction of our systems for a very short duration. Please note, no data or information was exposed or compromised during this event,” BYJU’S CTO Anil Goel said. 

“Our technical team has promptly resolved this issue as soon as it came to our notice. We would like to reiterate that all our systems have been built around safeguarding the privacy and security of our data,” Goel added.

Back in 2021, a similar case was reported with BYJU’S data that involved a security lapse and “this time it is much worse”, Diachenko’s post on X said. 

Diachenko told TechCrunch there were several IP addresses with the misconfigured server that enabled anyone to access the queue to read the students’ records without a password.

The company used the misconfigured Apache Kafka server to send and receive data in real time, he said. 

The misconfiguration was apparently fixed after the researcher’s post on X.

Earlier in 2020, personal data of 2.8 Lakh students and teachers enrolled on BYJU’S-owned WhiteHat Jr was reportedly exposed due to vulnerabilities in the company’s server.

Diachenko reportedly claimed 1 Mn-2 Mn records were accessible due to the latest issue at the startup.

BYJU’S Many Troubles

The incident adds to the woes of BYJU’S, which has been plagued with multiple controversies and issues pertaining to corporate governance, funding crunch, layoffs, delay in filing financial statements, and $1.2 Bn Term Loan B.

The beleaguered edtech decacorn also witnessed a major overhaul of its board and core team recently.

In June this year, three of its board members, including GV Ravishankar, MD of early-backer Peak XV Partners, resigned, along with representatives of Prosus and Chan Zuckerberg Initiative. 

BYJU’S former auditor Deloitte also quit from its role citing the delay in the filing the financial statements for FY22.

The company’s SVP for international business, Cherian Thomas, left the company this month.

Meanwhile, the startup recently roped in former Infosys executive VP and HR head Richard Lobo as an exclusive advisor in an attempt to transform its HR function. BYJU’S has also hired former upGrad CEO Arjun Mohan as the CEO of its international business. 

The edtech company also appointed former SBI Chairperson Rajnish Kumar and ace investor TV Mohandas Pai as members of its advisory council in July.

The post Security Researcher Claims Tech Glitch Exposed BYJU’S Students’ Data; Co Denies Leaks appeared first on Inc42 Media.

by Siliconluxembourg

Would-be entrepreneurs have an extra helping hand from Luxembourg’s Chamber of Commerce, which has published a new practical guide. ‘Developing your business: actions to take and mistakes to avoid’, was written to respond to  the needs and answer the common questions of entrepreneurs.  “Testimonials, practical tools, expert insights and presentations from key players in our ecosystem have been brought together to create a comprehensive toolkit that you can consult at any stage of your journey,” the introduction… Source link

by WIRED

B&H Photo is one of our favorite places to shop for camera gear. If you’re ever in New York, head to the store to check out the giant overhead conveyor belt system that brings your purchase from the upper floors to the registers downstairs (yes, seriously, here’s a video). Fortunately B&H Photo’s website is here for the rest of us with some good deals on photo gear we love. Save on the Latest Gear at B&H Photo B&H Photo has plenty of great deals, including Nikon’s brand-new Z6III full-frame… Source link

by Gizmodo

Long before Edgar Wright’s The Running Man hits theaters this week, the director of Shaun of the Dead and Hot Fuzz had been thinking about making it. He read the original 1982 novel by Stephen King (under his pseudonym Richard Bachman) as a boy and excitedly went to theaters in 1987 to see the film version, starring Arnold Schwarzenegger. Wright enjoyed the adaptation but was a little let down by just how different it was from the novel. Years later, after he’d become a successful… Source link