Close Menu
Xarkas BlogXarkas Blog
    What's Hot

    Early Pokemon Pokopia Prototype Leaks Online

    October 29, 2025

    Kia’s Funky PV5 Electric Van Blew Past Its Official Range—With A Full Load

    October 29, 2025

    Rising ID Crime Losses Take a Growing Emotional Toll

    October 29, 2025
    Facebook X (Twitter) Instagram
    Xarkas BlogXarkas Blog
    • Tech News

      Rising ID Crime Losses Take a Growing Emotional Toll

      October 29, 2025

      LG Uplus is latest South Korean telco to confirm cybersecurity incident

      October 29, 2025

      Flipkart’s Super.money teams up with Kotak811 to make India’s free UPI payments pay

      October 29, 2025

      CEO of spyware maker Memento Labs confirms one of its government customers was caught using its malware

      October 29, 2025

      Tata Motors confirms it fixed security flaws, which exposed company and customer data

      October 29, 2025
    • Mobiles

      iQOO 15 Colour Options, Q3 Gaming Chip, 144 FPS Gaming Confirmed via Amazon Listing

      October 29, 2025

      iQOO Neo 11R Could Launch in India as a Rebranded Neo 10 Pro with Dimensity 9400

      October 29, 2025

      Nothing Phone (3a) Lite India Price, Storage, and Sale Date Leaked Ahead of Tomorrow’s Global Launch

      October 29, 2025

      OPPO Find X9 Series India Launch Offers Revealed Ahead of Launch: Enco Buds 3 Pro+ to Tag Along

      October 29, 2025

      OPPO Find X9 and Find X9 Pro First Impressions

      October 28, 2025
    • Gaming

      Early Pokemon Pokopia Prototype Leaks Online

      October 29, 2025

      MoviePass opens fantasy league game Mogul to the public

      October 29, 2025

      Beginner Tips for PowerWash Simulator 2

      October 29, 2025

      Best GBA Pokemon Games

      October 29, 2025

      Mirror’s founder is back with a new ‘connected screen’ startup: a gaming device called ‘Board’

      October 29, 2025
    • SEO Tips
    • PC/ Laptops

      Apple-1 Computer, Initially Launched in 1976 for Approx. $667, Sold for Over Rs 3 Crore at an Auction

      October 29, 2025

      LG Electronics Launches New Smart Monitors In India: 27SR75U And 32SR75U

      October 29, 2025

      PC Shipments Grew 9.4% in Q1 2025, But Tariffs May Disrupt Momentum

      October 29, 2025

      Samsung Odyssey OLED G8, G9, and Odyssey 3D Gaming Monitors Launched in India: Check Price, Specs, Features

      October 29, 2025

      NVIDIA GeForce RTX 5060, RTX 5060 Ti Desktop GPU Launched with DLSS 4, Ray Tracing, GDDR7

      October 29, 2025
    • EV

      Kia’s Funky PV5 Electric Van Blew Past Its Official Range—With A Full Load

      October 29, 2025

      Honda’s Tiny EV Hot Hatch Pretends It Has A Gas Engine

      October 29, 2025

      Tesla Cybercab Might Come With A Steering Wheel After All

      October 29, 2025

      The Toyota Corolla Goes Electric—And Then Some

      October 29, 2025

      Our Best Look Yet At The Tesla Model Y Fighter

      October 29, 2025
    • Gadget
    • AI
    Facebook
    Xarkas BlogXarkas Blog
    Home - Featured - Tata Motors confirms it fixed security flaws, which exposed company and customer data
    Featured

    Tata Motors confirms it fixed security flaws, which exposed company and customer data

    KavishBy KavishOctober 29, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Tata Motors confirms it fixed security flaws, which exposed company and customer data
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Indian automotive giant Tata Motors has fixed a series of security flaws that exposed sensitive internal data, including personal information of customers, company reports, and data related to its dealers.

    Security researcher Eaton Zveare told TechCrunch that he discovered the flaws in Tata Motors’ E-Dukaan unit, an e-commerce portal for buying spare parts for Tata-made commercial vehicles. Headquartered in Mumbai, Tata Motors produces passenger cars, as well as commercial and defense vehicles. The company has a presence in 125 countries worldwide and seven assembly facilities, per its website.

    Zveare said he found that the portal’s web source code included the private keys to access and modify data within Tata Motors’ account on Amazon Web Services, the researcher said in a blog post.

    The exposed data, Zveare told TechCrunch, included hundreds of thousands of invoices containing customer information, such as their names, mailing addresses, and permanent account number, or PAN, a ten-character unique identifier issued by the Indian government.

    “Out of respect for not causing some type of alarm bell or massive egress bill at Tata Motors, there were no attempts to exfiltrate large amounts of data or download excessively large files,” the researcher told TechCrunch.

    There were also MySQL database backups and Apache Parquet files that included various bits of private customer information and communication, the researcher noted.

    The AWS keys also enabled access to over 70 terabytes of data related to Tata Motors’ FleetEdge fleet-tracking software. Zveare also found backdoor admin access to a Tableau account, which included data of over 8,000 users.

    Techcrunch event

    San Francisco
    |
    October 27-29, 2025

    “As server admin, you had access to all of it. This primarily includes things like internal financial reports, performance reports, dealer scorecards, and various dashboards,” the researcher said.

    The exposed data also included API access to Tata Motors’ fleet management platform, Azuga, which powers the company’s test drive website.

    Shortly after discovering the issues, Zveare reported them to Tata Motors through the Indian computer emergency response team, known as CERT-In, in August 2023. Later in October 2023, Tata Motors told Zveare that it was working on fixing the AWS issues after securing the initial loopholes. However, the company did not say when the issues were fixed.

    Tata Motors confirmed to TechCrunch that all the reported flaws were fixed in 2023, but would not say if it notified affected customers that their information was exposed.

    “We can confirm that the reported flaws and vulnerabilities were thoroughly reviewed following their identification in 2023 and were promptly and fully addressed,” said Tata Motors communications head Sudeep Bhalla, when contacted by TechCrunch.

    “Our infrastructure is regularly audited by leading cybersecurity firms, and we maintain comprehensive access logs to monitor for unauthorized activity. We also actively collaborate with industry experts and security researchers to strengthen our security posture and ensure timely mitigation of potential risks,” said Bhalla.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Kavish
    • Website

    Related Posts

    Early Pokemon Pokopia Prototype Leaks Online

    October 29, 2025

    Kia’s Funky PV5 Electric Van Blew Past Its Official Range—With A Full Load

    October 29, 2025

    Rising ID Crime Losses Take a Growing Emotional Toll

    October 29, 2025

    Apple-1 Computer, Initially Launched in 1976 for Approx. $667, Sold for Over Rs 3 Crore at an Auction

    October 29, 2025

    MoviePass opens fantasy league game Mogul to the public

    October 29, 2025

    iQOO 15 Colour Options, Q3 Gaming Chip, 144 FPS Gaming Confirmed via Amazon Listing

    October 29, 2025

    Comments are closed.

    Top Reviews
    Editors Picks

    Early Pokemon Pokopia Prototype Leaks Online

    October 29, 2025

    Kia’s Funky PV5 Electric Van Blew Past Its Official Range—With A Full Load

    October 29, 2025

    Rising ID Crime Losses Take a Growing Emotional Toll

    October 29, 2025

    Apple-1 Computer, Initially Launched in 1976 for Approx. $667, Sold for Over Rs 3 Crore at an Auction

    October 29, 2025
    About Us
    About Us

    Email Us: info@xarkas.com

    Facebook Pinterest
    © 2025 . Designed by Xarkas Technologies.
    • Home
    • Mobiles
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.