Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
cloud-misconfigurationai-platform-securityidentity-authentication-vulnerabilityinternet-exposed-service

Multiple Misconfiguration and Access-Control Flaws Expose AI and SaaS Platforms to Data Theft and Account Takeover

Updated 3mo agoFirst seen Feb 1, 20264 sources

Security researchers reported a critical Moltbook exposure caused by an unauthenticated database/API access issue that allowed enumeration of agent records (e.g., GET /api/agents/{id}) and leakage of email addresses, JWT login_tokens, and third-party api_keys, enabling agent hijacking and downstream abuse of connected services. Separately, Cal.com Cloud was found vulnerable to a chained set of broken access controls and signup/invite-token logic flaws that enabled complete account takeover and access to sensitive booking data (attendee details, emails, and booking histories) at scale, including organizational accounts.

In parallel, SentinelLabs documented that roughly 175,000 internet-exposed Ollama instances were reachable due to common deployment misconfiguration (binding to 0.0.0.0/public interfaces), creating conditions for arbitrary code execution and access to external resources—especially where tool-calling features were enabled. A distinct IoT case study described Molekule air purifiers exposing fleet-wide telemetry because an AWS Cognito Identity Pool permitted unauthenticated access to AWS IoT Core MQTT subscriptions, leaking device shadow data (e.g., Wi‑Fi SSIDs, MAC addresses, device names, sensor readings) for ~100,000 devices; the disclosed policy reportedly allowed read/subscribe access but not device control without per-device certificates.

Share:
Multiple Misconfiguration and Access-Control Flaws Expose AI and SaaS Platforms to Data Theft and Account Takeover
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Feb 1, 20265mo ago

Moltbook reportedly remains unpatched and unresponsive to disclosure

The Moltbook report states the company had not confirmed any patch and was unresponsive to vulnerability disclosures at the time of publication. Researchers recommended revoking exposed keys, sandboxing agents, and auditing for compromise.

Researchers disclose Moltbook data exposure and mass fake-account abuse

By February 1, 2026, researchers reported that Moltbook exposed email addresses, login tokens, and API keys through an unauthenticated API or database misconfiguration with predictable agent IDs. They also said the platform lacked account-creation rate limiting, allowing a single OpenClaw agent to create hundreds of thousands of fake accounts and inflate user counts.

Jan 30, 20265mo ago

Researchers report 175,000 Ollama servers exposed to the internet

On January 30, 2026, SentinelLABS reported that roughly 175,000 Ollama hosts were publicly accessible, often because administrators changed the default local-only bind setting to a public interface. The report warned that exposed tool-calling and weak authentication could enable remote code execution and unauthorized access to external systems.

Jan 29, 20265mo ago

Researcher discloses unauthenticated MQTT access in Molekule air purifiers

A vulnerability report published on January 29, 2026 described unauthenticated access to the MQTT broker used by Molekule IoT air purifiers. The disclosure indicates the devices' messaging infrastructure could be reached without authentication.

Cal.com patches account takeover in version 6.0.8

Cal.com said it fixed the account takeover issue in version 6.0.8 after the flaws were identified. Additional fixes to restrict internal route handler access were released within days to address related exposure paths.

Jan 26, 20265mo ago

Gecko Security discovers chained Cal.com account takeover flaws

On January 26, 2026, researchers reported discovering three connected vulnerabilities in Cal.com Cloud, including broken invite-flow validation and an IDOR issue. The chain allegedly allowed attackers to overwrite victim passwords, hijack accounts, and access or delete booking data.

Jan 25, 20265mo ago

Moltbook launches in late January 2026

Moltbook, an AI-agent social network created by Octane AI's Matt Schlicht, launched in late January 2026. The later vulnerability report ties exposed data and account abuse to this newly launched platform.

Apr 12, 20251y ago

SentinelLABS and Censys begin long-term scan of exposed Ollama hosts

Researchers from SentinelLABS, working with Censys, conducted a 293-day internet scanning effort to measure public exposure of Ollama servers. Over the course of the study they recorded 7.23 million observations across 130 countries and 4,032 autonomous system networks.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

4 LINKEDOpen in app
Organizations
4 linked
AnthropicOctane AICensysSentinelOne
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Multiple Misconfiguration and Access-Control Flaws Expose AI and SaaS Platforms to Data Theft and Account Takeover | Mallory