By using this site, you agree to the Privacy Policy and Terms of Use.
Accept

The Morning News informer

Perfect for news, magazine, blog and for all kinds of publishing websites

  • Latest News
  • World News
    • America
    • China
    • Russia
    • UAE
    • Asia
  • All India News
    • South India
    • North India
    • Delhi
    • Mumbai
  • Sports
    • Cricket
      • T20 World Cup
      • IPL
    • Football
      • FiFA World Cup
    • World-cup
  • Entertainment
    • Celebrity
    • Movies
    • Movie Reviews
    • Travel
    • Special Events
    • Video Games
  • Technology
    • PC Hardware
    • Gadget
    • Tech News
    • Tech Reviews
  • Business & Finance
    • Business
    • Finance
    • Investment
    • Startup News
  • Health
    • Nutrition
    • Medicine
    • Beauty Tips
  • Life Styles
    • Fashion
    • Beauty Tips
    • Magazine
Reading: CyberX9 Flags Loopholes in Darwinbox System; Firm Denies Breach, Cites Client-Side Leaks
Share
Facebook Youtube Tumblr Threads Telegram Whatsapp
Font ResizerAa
The Morning News InformerThe Morning News Informer
  • Latest News
  • World News
  • All India News
  • Sports
  • Entertainment
  • Technology
  • Business & Finance
  • Health
  • Life Styles
Search
  • Latest News
  • World News
    • America
    • China
    • Russia
    • UAE
    • Asia
  • All India News
    • South India
    • North India
    • Delhi
    • Mumbai
  • Sports
    • Cricket
    • Football
    • World-cup
  • Entertainment
    • Celebrity
    • Movies
    • Movie Reviews
    • Travel
    • Special Events
    • Video Games
  • Technology
    • PC Hardware
    • Gadget
    • Tech News
    • Tech Reviews
  • Business & Finance
    • Business
    • Finance
    • Investment
    • Startup News
  • Health
    • Nutrition
    • Medicine
    • Beauty Tips
  • Life Styles
    • Fashion
    • Beauty Tips
    • Magazine
Follow US
© 2025 The Morning News Informer. All Rights Reserved.
The Morning News Informer > Blog > Business & Finance > Startup News > CyberX9 Flags Loopholes in Darwinbox System; Firm Denies Breach, Cites Client-Side Leaks
Startup News

CyberX9 Flags Loopholes in Darwinbox System; Firm Denies Breach, Cites Client-Side Leaks

Writer
Last updated: May 1, 2025 9:01 am
Writer
Share
1746081054 articleshow
SHARE
CyberX9 ー CCompany
photo by cyberx9

In a recent cybersecurity report, CyberX9 flagged several vulnerabilities within the HR tech platform Darwinbox, which could expose sensitive data of both employees and job applicants. Despite the report’s alarming findings, Darwinbox has strongly denied any breach on its platform, attributing the issue to client-side credential theft and leaks from the dark web.

Contents
🔍 CyberX9’s Findings: Vulnerabilities and Data Exposure⚠️ Darwinbox’s Response: Denial of Breach and Client-Side Issues💬 Statement from CyberX9🔐 What’s Next for Darwinbox and Cybersecurity in HR Tech?

🔍 CyberX9’s Findings: Vulnerabilities and Data Exposure

CDSL Data Breach Exposed Data of 4.39 Crores Investors According to CyberX9
photo by angel one

The cybersecurity firm discovered multiple vulnerabilities that could potentially expose critical Personal Identification Information (PII) of employees working at client organizations using Darwinbox’s HR application. The exposed data reportedly includes full names, phone numbers, email addresses, job titles, locations, photos, and even resumes of job applicants.

CyberX9 revealed that an endpoint within the Darwinbox system allowed unauthorized access to sensitive data by exploiting employee IDs, which are sequentially assigned within the platform. The company also found that leaked credentials from a Typeform account—created by Darwinbox’s career team—were linked to a prior breach on the Typeform platform in 2024. This led to the exposure of resumes and sensitive personal information from applicants.

⚠️ Darwinbox’s Response: Denial of Breach and Client-Side Issues

In response to the vulnerabilities flagged by CyberX9, Darwinbox has issued a firm denial, stating that the issue did not stem from any breach within its platform. Instead, the company attributes the data leak to credential theft occurring on the client side, due to prior leaks on forums like BreachForums and potential malware infections on users’ personal devices.

Darwinbox confirmed that their systems remain secure, and no unauthorized access or compromise of infrastructure occurred on their end. The company also emphasized that the data endpoint vulnerability mentioned in the report only affects users within their organization and that they have implemented fixes to address the issues raised.

💬 Statement from CyberX9

Himanshu Pathak, founder and MD of CyberX9, questioned the security practices of Darwinbox, specifically regarding the failure to change leaked credentials. He asked, “If Darwinbox knew about these leaked credentials, why didn’t they take action to protect their users’ sensitive data?”

Despite these concerns, CyberX9 acknowledged that Darwinbox had worked to implement fixes for the vulnerabilities. However, the firm raised concerns about whether Darwinbox’s response was adequate and whether the platform had been fully transparent in addressing the potential risks.

🔐 What’s Next for Darwinbox and Cybersecurity in HR Tech?

In a broader context, this incident highlights ongoing concerns in the HR tech industry about securing sensitive employee and applicant data. As companies increasingly adopt digital HR platforms like Darwinbox, ensuring robust cybersecurity practices is more critical than ever. Although Darwinbox has stated that it has implemented necessary fixes, the cybersecurity community will continue to watch closely as further investigations and audits unfold.

As a precautionary measure, CyberX9 has recommended enhanced security measures for organizations using Darwinbox, including limiting API requests and further strengthening security protocols at the client level to avoid such breaches in the future.

The case also highlights the importance of constant vigilance against client-side vulnerabilities, as attackers often target individual users through methods such as malware or phishing. As the HR tech landscape grows, maintaining robust data protection strategies will be essential to ensuring both organizational and customer trust.

Stay tuned as we continue to monitor updates on this ongoing security issue.

“The user’s login credentials were exposed through prior leaks publicly available on BreachForums, likely due to malware infections on users’ personal devices. Our investigation into the said report confirms that Darwinbox’s systems remain secure and safe. No unauthorised access or infrastructure compromise has occurred on Darwinbox’s side,” the company said.

In its communication to CyberX9, the HR tech firm has also stated that the end data point vulnerability highlighted in the report is limited to users operating within their organisation and agreed that enhancing rate limits (layers of information that an employee can access) can further enhance protection against the risk.

Recent News

  • AI+ Nova 5G & Pulse India Launch on July 8: Price, Specs Teased
  • Realme 15 5G and 15 Pro 5G Launching Soon in India With AI Features
  • Baidu to Open-Source Ernie AI Model Today, Marking China’s DeepSeek Moment
  • Bandai Namco Summer Showcase to Reveal New My Hero Academia Game
  • Gmail Adds Manage Subscriptions on Web, Mark as Read on Android
TAGGED:client-side credential theftcybersecurity 2025CyberX9 vulnerabilityDarwinbox security breachdata protectionHR tech data leak
Share This Article
Email Copy Link Print
Share
Previous Article uZFueQZkFImoYEzeDEJJ UPI Transactions See Marginal Dip to 17.89 Billion in April 2025
Next Article AI Lab LLM Scaling Business These Startups Are Building Advanced AI Models Without Data Centers
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest News

Oponion

Rain in city 6 1747792813454 1747792826961 1

Heavy Rainfall in Mumbai, Bengal; Thunderstorms Forecast for Delhi and South India: IMD Alert

The India Meteorological Department (IMD) has issued a high-alert weather…

May 31, 2025
why india grounding turkish aviation firm celebi is a seismic security shift 184734642 16x9 0

India Blocks Turkish Firm Çelebi on Security Grounds: No Explanation Given

Introduction In a significant development with geopolitical implications, the Indian…

June 3, 2025
article

2 Terrorists Linked to 2023 Pune Conspiracy Arrested in Mumbai

Introduction The National Investigation Agency (NIA) has apprehended two operatives…

June 1, 2025
images 41

Ukraine and Russia Hold First Direct Talks Since 2022, Agree on 1,000 Prisoner Swap

For the first time in over three years, Ukrainian and…

May 31, 2025
freepik export 20240501163758a0i6

Top 6 Ways AI Reduces Workplace Burnout and Boosts Productivity

Introduction Workplace burnout is more than a buzzword—it's a growing…

June 3, 2025
Previous Next
The Morning news informer

Perfect for news, magazine, blog and for all kinds of publishing websites

News

Latest News

World News

India News

International Affairs

Sports

Cricket

Football

T20 World Cup

IPL

Technology

Tech News

Gadget

PC Hardware

Innovate

Entertainment

Movies

Celebrity News

Screen Entertainment

Videos Games

Health & Lifestyle

Health & Lifestyle

Nutrition

Beauty Tips

Children

Business

Business

Finance

Investment

Startup News

Privacy Policy

Cookie Policy

Terms And Conditions

Contact US

Facebook Youtube Tumblr Threads Telegram Whatsapp

© The Morning News Infomer. All Rights Reserved

Go to mobile version
Username or Email Address
Password

Lost your password?