Close Menu
Core Bulletin

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Former Googlers’ AI startup OpenArt now creates ‘brain rot’ videos in just one click

    August 9, 2025

    How to Watch Outside Lands 2025 Live Stream Online

    August 9, 2025

    Hailey Bieber Amps up Date Night Style for a Celebrity Favorite Spaghetti Spot

    August 9, 2025
    Facebook X (Twitter) Instagram
    Core BulletinCore Bulletin
    Trending
    • Former Googlers’ AI startup OpenArt now creates ‘brain rot’ videos in just one click
    • How to Watch Outside Lands 2025 Live Stream Online
    • Hailey Bieber Amps up Date Night Style for a Celebrity Favorite Spaghetti Spot
    • 2025 fantasy football draft guide – Rankings, mock drafts and analysis
    • Police officer dies after shooting near US’s CDC headquarters
    • Lammy and Vance to hold meeting to discuss US-brokered Ukraine peace plan | Ukraine
    • ‘It’s missing something’: AGI, superintelligence and a race for the future | Artificial intelligence (AI)
    • 3 Best Steam Mops, Tested for Months (2025)
    Saturday, August 9
    • Home
    • Business
    • Health
    • Lifestyle
    • Politics
    • Science
    • Sports
    • Travel
    • World
    • Technology
    • Entertainment
    Core Bulletin
    Home»Technology»A Misconfiguration That Haunts Corporate Streaming Platforms Could Expose Sensitive Data
    Technology

    A Misconfiguration That Haunts Corporate Streaming Platforms Could Expose Sensitive Data

    By Liam PorterAugust 8, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
    A Misconfiguration That Haunts Corporate Streaming Platforms Could Expose Sensitive Data
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Top streaming services like Netflix and Disney+ have made sustained investments over the years to lock their content down. Whenever they can, they prevent users from accessing videos without a subscription or watching region-blocked content. New findings presented today at the Defcon security conference in Las Vegas, though, indicate that streaming platforms used for things like internal corporate broadcasts and sports livestreams can contain basic design flaws that allow anyone to access a vast swath of content without logging in.

    Independent researcher Farzan Karimi first realized years ago that misconfigurations in application programming interfaces, or APIs, exposed streaming content to unauthorized access. In 2020 he disclosed a set of such flaws to Vimeo that could have allowed him to access close to 2,000 internal company meetings along with other types of livestreams. The company quickly fixed the issue at the time, but the finding left Karimi with concerns that similar problems could be lurking in other platforms.

    Years later, he realized that by refining a technique for mapping how APIs retrieve data and interact, he could look for other vulnerable platforms. At Defcon, Karimi is presenting findings about current exposures in one mainstream sports streaming platform—he is not naming the site because the issues are not yet resolved—and releasing a tool to help others identify the problem in additional sites.

    “For a company all hands or other sensitive meeting, there might be key internal information being shared—CEOs or other executives talking about layoffs or sensitive intellectual property,” Karimi told WIRED ahead of his conference talk. “You can see a bad pattern emerge in how easily you can circumvent authentication to access streams, but this class of issue was previously dismissed as requiring deep knowledge of a given business to identify.”

    APIs are services that fetch and return data to whoever requests it. Karimi gives the example that you can search for the movie Fight Club on a streaming platform, and the stream for the movie may come back with information about the length of the movie, trailers, actors in the movie, and other metadata. Multiple APIs work together to assemble all of this information with each fetching certain types of data. Similarly, if you search for Brad Pitt, a set of APIs will interact to deliver Fight Club along with other movies he’s starred in like Troy and Seven. Some of these APIs are designed to require proof of authentication before they will return results, but if a system hasn’t been scrutinized deeply, it is common for other APIs to blindly return data without requiring proof of authorization on the assumption that only an authenticated requestor will be in a position to send queries.

    “Often there are basically four, five, some number of APIs that have all this metadata, and if you know how to trace through them, you can unlock paywalled content for free,” Karimi says. “It’s a ‘security through obscurity’ model where they would never think that someone would be able to manually connect the dots between these APIs. The automation I’m introducing, though, helps find these authorization flaws quickly at scale.”

    Karimi emphasizes that top streaming services are largely locked down and either corrected such API misconfigurations long ago or avoided them from the start. But he emphasizes that more utilitarian platforms for corporate streaming and other live events—including always-on cameras in sports arenas and other venues that are meant to only be accessible at certain times—are likely vulnerable and exposing video that is thought to be protected.

    corporate Data Expose haunts Misconfiguration platforms Sensitive streaming
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Liam Porter
    • Website

    Liam Porter is a seasoned news writer at Core Bulletin, specializing in breaking news, technology, and business insights. With a background in investigative journalism, Liam brings clarity and depth to every piece he writes.

    Related Posts

    Former Googlers’ AI startup OpenArt now creates ‘brain rot’ videos in just one click

    August 9, 2025

    3 Best Steam Mops, Tested for Months (2025)

    August 9, 2025

    Tesla Robotaxi scores permit to run ride-hailing service in Texas

    August 9, 2025

    Microsoft investigates Israeli military’s use of Azure cloud storage | Microsoft

    August 9, 2025

    Everything you need to know about the new iPhone and iPad update

    August 9, 2025

    RIP, Microsoft Lens, a simple little app that’s getting replaced by AI

    August 9, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Medium Rectangle Ad
    Don't Miss
    Technology

    Former Googlers’ AI startup OpenArt now creates ‘brain rot’ videos in just one click

    August 9, 2025

    AI-generated “brain rot” videos are popping up all over the internet and getting a lot…

    How to Watch Outside Lands 2025 Live Stream Online

    August 9, 2025

    Hailey Bieber Amps up Date Night Style for a Celebrity Favorite Spaghetti Spot

    August 9, 2025

    2025 fantasy football draft guide – Rankings, mock drafts and analysis

    August 9, 2025
    Our Picks

    Reform council confirms ‘patriotic’ flag policy

    July 4, 2025

    Trump references bankers with antisemitic slur in Iowa speech to mark megabill’s passage – as it happened | Donald Trump

    July 4, 2025

    West Indies v Australia: Tourists bowled out for 286 in Grenada Test

    July 4, 2025

    Beards may be dirtier than toilets – but all men should grow one | Polly Hudson

    July 4, 2025
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Medium Rectangle Ad
    About Us

    Welcome to Core Bulletin — your go-to source for reliable news, breaking stories, and thoughtful analysis covering a wide range of topics from around the world. Our mission is to inform, engage, and inspire our readers with accurate reporting and fresh perspectives.

    Our Picks

    Former Googlers’ AI startup OpenArt now creates ‘brain rot’ videos in just one click

    August 9, 2025

    How to Watch Outside Lands 2025 Live Stream Online

    August 9, 2025
    Recent Posts
    • Former Googlers’ AI startup OpenArt now creates ‘brain rot’ videos in just one click
    • How to Watch Outside Lands 2025 Live Stream Online
    • Hailey Bieber Amps up Date Night Style for a Celebrity Favorite Spaghetti Spot
    • 2025 fantasy football draft guide – Rankings, mock drafts and analysis
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Disclaimer
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions
    © 2025 Core Bulletin. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.