#blob

silverwuffamutewuffaf.at@bsky.brid.gy
2025-07-08
2025-07-06

"Repeated data leak offender" - Looking for contacts in Malaysia

This #leak is a really weird story and I am looking for help in #Malaysia.

If I were in the medical business, I would be very careful about what pictures of my customers I store longterm. And there would be tons of safeguards before I would allow them to be stored in a bucket (#Microsoft #Azure #Blob in this case). At the very least I would make sure that the Blob IS NOT world readable and world indexable. Should this ever happen to me, I would be so deeply ashamed that this shame would eternally prevent me from doing the same mistake again. Doing this over and over again takes the approach to IT security and privacy protection to a new low.

This brings us to BP Healthcare, a Malaysian healthcare giant that runs a multitude of businesses in that country. This includes online health services, laboratories, pharmacies, dental clinics, eye centers and much, much more. According to their own publications, they serve 35 million customers. Furthermore they seem to rely heavily on cloud services.

While other data leaks (at least four we know of) inside the sprawling empire of BP Healtcare since April 2019 were mostly fixed in a timely fashion (but without ever acknowledging the problem or answering at all), we currently see no less than three Azure blobs with a gigantic amount of data on which (even though the security researcher inquired multiple times) no action is forthcoming.

The data includes

  • One Blob with 1.5 million prescriptions, receipts and invoices
  • One Blob with 1.7 milltion invoices for healthcare services
  • One Blob with 1.8 million assorted documents

The last blob is the most critical as it seems tied to a medical service provided via chat. The blob contains (among other) things images customers uploaded to show their medical problems. Naturally this includes their customers being in varying state of undress. Surprisingly, a lot of the telemedicine chats involved named patients seeking diagnosis or treatment for sexually transmitted diseases.

We are looking for a government agency (or contact in the technical press) that would take a long hard look at all the ITZ operations of BP healthcare. The fact that we see the same problem occurring again and again worries us deeply. Sometimes it is even the same subsidary that is having the same problem. Furthermore they are exposing the most intimate information about the customers. There are several warning signs, that the trouble may run deeper than just these leaks.

Closing remark: I usually do a PostMortem of the data leak including the URL of the leak that was closed. This will not happen in this case. Even a first glance at the cloud infrastructure paints a worrying picture and we are not confident that they will not reopen (assumed they close it in the first place) the leak at some point in the future. Thererefore I will abstain from naming it in the report.

Petra van CronenburgNatureMC@mastodon.online
2025-07-04

Sometimes, when I interview bacteria or animals, I ask myself if it's not too childish. But hey, the highly respected @cnrs lets #blobs talk!
In case you need some #goodNews: Blobs are sure to take over the world (well, my hypothesis). Thanks to the CNRS and a #citizenScience project, they are already living in countless children's bedrooms. đŸ€« Listen to a blob: youtube.com/watch?v=Dwcx6yCdDE8

#NatureMatchCuts #blob #PhysarumPolycephalum #slimeMould #learning #intelligence #moreThanHuman

2025-07-01
2025-06-25
Medicinart capsule 017/438 Title: Blobbing The Blob
#art #handmade #noai #pocketsized #analogue #healing #blobbing #blob #waxpastels
2025-06-23
Giuseppe CeddĂŹateach77
2025-06-20

Stanotte 1:40 / Rai 3
Fuori Orario, cose (mai) viste:

Asako I & II
(R. Hamaguchi, 2018)


たくăČあいmiku39rock69lain77to@voskey.icalo.net
2025-06-19
Stefanie Janine Stöltingsjstoelting@digitalcourage.social
2025-06-16

Just published a second blog post about #PostgreSQL #BLOB|s covering another method, that I would not advise to use.
proopensource.it/blog/postgres

2025-06-15

Yo les nerds de mastodon, j'ai ramassĂ© ça en forĂȘt, ou pas blob ?

Un truc bien jaune accroché du bois vermoulu
2025-06-03

Le club escalade de La Perm.

3 juin 2025, 15:45:00 CEST - GMT+2

mobilizon.picasoft.net/events/

BannerIMG_20250531_181137.jpgIMG_20250531_181207.jpg
icarolongoicarolongo
2025-05-31
Vhen â„ïžđŸŠŠfoxvhen@wobbl.xyz
2025-05-29
Giuseppe CeddĂŹateach77
2025-05-23

Stanotte su rai 3 dall'1:40 / fuori orario cose (mai) viste...

2025-05-22

(16/18) ... milliers d'animaux + dizaine de personnes hospitalisées + population locale en
- Irma ßles de Saint-Martin + de Saint-Barthélemy.
- vague de océanique depuis 2014 = décÚs 4 millions de guillemots de Troïl plage Alaska + capelan/ammodyte/morues + baleines à bosse-> danger écosystÚmes.
- France : loi n° 2016-925 du 7 juillet 2016 classement au titre des sites ...

Équations impĂ©nĂ©trables, courbes Ă©nigmatiques, raisonnements nĂ©buleux
 L’économie dominante invite Ă  un double renoncement : devant les difficultĂ©s techniques d’un univers rĂ©servĂ© aux experts, d’une part ; devant des « lois » scientifiques immuables, de l’autre.

Le contre-manuel du « Monde diplomatique » entend inverser cette logique. Son ambition ? Rendre l’économie accessible au plus grand nombre et en souligner la nature politique. Bref, rappeler que, comme la chose publique, l’économie est l’affaire de tous. Et permettre Ă  chacun de s’en emparer.
2025-05-09

New phishing trick uses blob URIs to load fake login pages inside your browser. Even trusted links like OneDrive can lead you there.

Read: hackread.com/phishing-attack-b

#CyberSecurity #Phishing #Scam #Blob #InfoSec

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst