User data, including explicit content, exposed by online video downloader

Published:

spot_img

Dirpy’s Misconfiguration Exposes User Data: IP Addresses and Explicit Content Leaked

The Cybernews research team recently uncovered a major security breach at Dirpy, an online video downloader service. The team found an open Kibana instance belonging to Dirpy, exposing sensitive user data to potential threats. Dirpy, known for its video downloading service for YouTube and adult websites, failed to properly secure its system, leading to the leak of 15.7 million entries of private data.

The leaked data included user IP addresses, premium user account IDs, activity logs with downloaded content (including explicit material), URLs of requested content, and user diagnostic information. This breach raised concerns about user privacy and security, especially considering the nature of the downloaded content.

The exposed data was available from March 18th to April 24th, 2024, until the Cybernews team alerted Dirpy and access to the instance was secured. The leak highlighted the importance of proper cybersecurity measures and the potential risks of leaving systems vulnerable to unauthorized access.

Dirpy’s failure to secure its system serves as a reminder of the importance of safeguarding personal information online. The incident underscores the need for users to exercise caution when using online services and consider using VPNs or secure proxies to protect their data from potential breaches. Cybernews has reached out to Dirpy for an official comment on the breach but has not received a response yet.

spot_img

Related articles

Recent articles

Microsoft patches record 622 vulnerabilities, including two actively exploited zero-days

Microsoft has issued a significant security update, addressing a record 622 vulnerabilities in its products, including two actively exploited zero-day vulnerabilities. This update, part...

Romania’s Land Registry Agency Works to Restore Services Following Cyberattack Disruption

A cyberattack has disrupted Romania's digital land registry systems, as reported by the National Agency for Cadastre and Land Registration (ANCPI). The agency confirmed...

CVE-2026-56164 and CVE-2026-56155 in Microsoft SharePoint and Active Directory Patches Released Amid Active Exploitation Concerns

On July 20, 2026, Microsoft released critical patches addressing two vulnerabilities, CVE-2026-56164 and CVE-2026-56155, affecting SharePoint Server and Active Directory Federation Services, respectively. These...

Abbott Laboratories Investigates Dual Cybersecurity Breaches Linked to ShinyHunters and ShadowByt3$

Abbott Laboratories is currently investigating two significant cybersecurity incidents affecting its Cancer Diagnostics and Core Laboratory diagnostics businesses. The first incident involves unauthorized access...