"A YC-Backed Startup Left Production AWS Keys Public for 5 Months. Their VDP Was Silent."

https://benzimmermann.dev/blog/pump-vdp-silence

#security #infosec #yc #cybersecurity

A YC-Backed Startup Left Production AWS Keys Public for 5 Months. Their VDP Was Silent. - Ben Zimmermann

Pump.co's full production environment file was publicly exposed for 5 months. They silently fixed it and never responded to the disclosure.