慣性聚合 高效追讀感興趣之博客、新聞、科技資訊
閱原文 以慣性聚合開啟

推薦訂閱源

小众软件
小众软件
博客园 - 叶小钗
有赞技术团队
有赞技术团队
大猫的无限游戏
大猫的无限游戏
博客园_首页
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
L
LangChain Blog
Hugging Face - Blog
Hugging Face - Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
aimingoo的专栏
aimingoo的专栏
Blog — PlanetScale
Blog — PlanetScale
爱范儿
爱范儿
T
Tailwind CSS Blog
Jina AI
Jina AI
量子位
Stack Overflow Blog
Stack Overflow Blog
人人都是产品经理
人人都是产品经理
J
Java Code Geeks
V
Visual Studio Blog
月光博客
月光博客

TechCrunch

Robots beat human records at Beijing half-marathon Palantir posts mini-manifesto denouncing inclusivity and ‘regressive’ cultures TechCrunch Mobility: Uber enters its assetmaxxing era Cracks are starting to form on fusion energy’s funding boom Blue Origin successfully re-uses a New Glenn rocket for the first time ever Tesla brings its robotaxi service to Dallas and Houston VC Ron Conway says he has a ‘rare form of cancer’ AI chip startup Cerebras files for IPO Anthropic’s relationship with the Trump administration seems to be thawing The App Store is booming again, and AI may be why “Tokenmaxxing” is making developers less productive than they think Hackers are abusing unpatched Windows security flaws to hack into organizations Zoom teams up with World to verify humans in meetings Gigs turns your concert history into a personal live music archive Chef Robotics escaped the robot cooking graveyard and says it’s thriving — here’s why Uber will now pick up your returns from your doorstep Anthropic launches Claude Design, a new product for creating quick visuals Google’s AI Mode can now help you find products in stock nearby Bluesky confirms DDoS attack is cause of continued app outages Bluesky confirms DDoS attack is cause of continued app outages Netflix plans to add a vertical video feed, use AI for recommendations SaySo is a new short-form video app that aims to restore users’ trust in news Loop raises $95M to build supply chain AI that predicts disruptions Are we tokenmaxxing our way to nowhere? New leaders, new fund: Sequoia has raised $7B to expand its AI bets Netflix co-founder and chair Reed Hastings to leave board Upscale AI in talks to raise at $2B valuation, says report Physical Intelligence, a hot robotics startup, says its new robot brain can figure out tasks it was never taught From the Startup Battlefield stage to the International Space Station: geCKo Materials built a sticky product Slash, a Ramp competitor founded by teenagers, raises $100M at $1.4B valuation OpenAI takes aim at Anthropic with beefed-up Codex that gives it more power over your desktop European police email 75,000 people asking them to stop DDoS attacks Anthropic CPO leaves Figma’s board after reports he will offer a competing product Google now lets you explore the web side-by-side with AI Mode Two Americans sentenced for helping North Korea steal $5 million in fake IT worker scheme InsightFinder raises $15M to help companies figure out where AI agents go wrong AI traffic to US retailers rose 393% in Q1, and it’s boosting their revenue too Roblox’s AI assistant gets new agentic tools to plan, build, and test games Google adds Nano Banana-powered image generation to Gemini’s Personal Intelligence Google is now targeting bad ads over bad actors You’ve heard of hybrid cars. Now meet a hybrid cement plant. Runway CEO says AI could help Hollywood make 50 films instead of one $100M blockbuster Meta raises Quest 3 and Quest 3S prices due to RAM shortage Canva’s AI assistant can now call various tools to make designs for you Fashion retailer Express left customers’ personal data and order details exposed to the internet This simulation startup wants to be the Cursor for physical AI DeepL, known for text translation, now wants to translate your voice Amazon-backed X-energy files to raise up to $800M in IPO Ford EV and tech chief leaving automaker Wait, could they still actually break up Live Nation?
英签证网关泄数千申请人护照及自拍照 — 遂召律师诉之
Zack Whittak · 2026-05-28 · via TechCrunch

有网站名曰UK Visa Portal,公然泄露数千申请人护照及自拍照,此等申请人皆付费于该网站以求得英国移民签证,TechCrunch得闻此事。

有匿名者告于TechCrunch,言该网站至少暴露十万人之文件,此等人均将护照与自拍照上传于网站,作为申请之过程。

此网站与英國政府無關,,誤付此公司之費,非依官方GOV.UK網站行事

所泄之数据,于周三夜间获固,此乃吾辈初述此事数时之后。鉴于所泄数据之高度机密,TechCrunch披露正有安全隐忧,然隐其详实,以减损对个人私隐之再增风险。

TechCrunch 尚未得英国签证网管之音。吾等致书,彼非欲解此困,反遣律师及公关公司至吾处。

此安全之失,乃诸公司近数周公开其顾客之机密政府身份文书之又一例,多由配置之误而非外患所致。护照之泄露尤甚,适逢全球在线身份核查日增,盖因诸国颁行年岁验证之法之故。

公司之默然,亦存疑焉,其将告所涉客,其护照公然外泄乎?抑或依美利坚州及欧陆数据泄露通报律例,而报诸监管者乎?

护照外泄,自拍之图,位置之数

此数据泄露,起于公众之亚马孙托管存储服务器(亦称桶),英国签证门户用以托管用户上传之护照与自画像也。

虽桶不公然列其内物,然桶内之文仍可为人所知,惟其知各文件之网址耳。告我以暴露者云,英签证网之后台有弊,使彼得以观桶中所含文件之列。

TechCrunch既确证之,英签证网(亦称英伦之旅ETA-Pass乃数据泄密之由,且验其真伪,盖因询及受影响者,察其信息是否确实。

众多用户上传之照片,亦含天地实位,显其摄之所自;间有此位数据,精准至可露摄者之居所。

英國簽證網站不提供通過其網站報告安全問題之途,亦未於其網站上列示公司管理層之名諱或聯繫資訊。TechCrunch致函英國簽證網站所列之電子郵件地址,告之公司存在持續之安全漏洞,並詢問管理層何人可與之共享細節以解決此問題。TechCrunch解釋,吾等不能與公司之通用客戶支持信箱共享具體信息,因無法保證所暴露之數據不至被濫用。

客服人员向 TechCrunch 提供了迈克尔·泰勒之名与邮箱,闻其乃英国签证网之经理。此人未应吾等之询。

未几,美利坚律所BakerHostetler之律师及FTI Consulting公关公司之代表,皆诣TechCrunch,欲询英国签证网关之失。TechCrunch诘之,律师等不肯示以授权之证,如示以公牍,明其所代表者之姓名职司。吾复申之,谓公司管理层外,不得泄其安危之失。 

吾等言,若泰勒,或他管事者,愿闻此安全之失,则可相询——或律士可抄附于邮件之链。吾等未闻复音。

吾等之文既发,桶亦得固,TechCrunch遂向律师团发问,询及安全之失。吾等所问BakerHostetler之合伙人Ryan Christian者,有云:亚马孙所托之桶,暴露几何时?其暴露之由何在?公司可有日志,以辨人是否得窥或下载其暴露之数据?吾等复问:UK Visa Portal中,孰司网络安全之事?若有人乎?Christian未应。 

英签证网关,据称由Active Leadgen LLC公司运营,该公司声称位于阿拉伯联合酋长国。TechCrunch未能独立核实此说。

申请英电子旅行授权,非必使用第三方服务,除非你聘有移民律师,申请人应通过英政府网站申请。.

初刊于五月廿六,后增补安全疏漏之信息而更之。

若于吾辈文章中所附链接处购之,吾等或可得微利此无伤吾辈编撰之独立。