Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Hackaday’s August 1, 2025 security roundup brings together several different kinds of security failure: exposed personal data, unsafe paths from AI tools to command execution, a reported bank intrusion, and an unverified allegation about Nvidia’s H20 GPU. The common thread is trust at a boundary—who can read data, run commands or reach a more privileged system—but the evidence is not the same in every story. Some incidents involved reported real-world exposure; others were security demonstrations, and the H20 story remained an allegation.

Tea: exposed images and a separate report of private messages

The Tea app stories concerned highly sensitive information, but the reported image exposure and the later message-database discovery should not be treated as one dataset. BleepingComputer reported that an unsecured Firebase storage bucket exposed images, including selfies and government identification submitted for verification, as well as material shared in the app. Tea said its legacy system held data from before February 2024 and that the dataset included approximately 72,000 images: around 13,000 selfies and photo IDs and 59,000 images viewable in the app. BleepingComputer described the exposed legacy data as exceeding 59 GB. BleepingComputer’s report reproduces Tea’s statement and distinguishes that dataset from a separate discovery.

In that separate discovery, BleepingComputer reported a database containing approximately 1.1 million private messages. The article also reported that a researcher said users’ API keys could access stored user data. Tea later told BleepingComputer that some direct messages had been accessed and that it took the affected system offline. The approximate message count is part of the separate reporting, not the image count in Tea’s statement.

The security issue is not simply that an app stored sensitive information. It is that storage and API authorization boundaries did not prevent access to material that users would reasonably expect to remain private. Collecting less sensitive information, limiting how long it is retained and checking authorization at each access point can reduce the consequences when one boundary fails.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

GiveWP: donor contact details appeared in page source

A separate incident affected Pi-hole donors through the GiveWP donation plugin. In its July 30, 2025 post-mortem, Pi-hole said donor names and email addresses were exposed in page source because of a GiveWP issue. Pi-hole said it did not have or store card numbers and that the Pi-hole product itself was not the breached system; this account is Pi-hole’s description of the incident.

Pi-hole said the vulnerability was reported on July 29 and that GiveWP released version 4.6.1 within a couple of hours of the report. Pi-hole also criticized the delay in official notification and how the impact was addressed. That release is a point-in-time detail from the post-mortem, not confirmation of the plugin’s current security status.

AI command execution: tool access changes the risk

Two linked stories examined risks that arise when AI assistants can use tools or run commands. The issue is not just whether a model produces an incorrect answer: if untrusted instructions can steer an assistant into an unsafe tool path, the assistant’s permissions can turn a misleading input into an action.

Gemini AI CLI hijack

Tracebit’s report, “Code Execution Through Deception: Gemini AI CLI Hijack,” describes a command-execution risk involving the Gemini AI CLI. It is a security-research account of a particular tool and execution path, not evidence that every AI assistant—or every configuration of this one—can be compromised in the same way.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Root access inside a Copilot Jupyter container

Eye Security’s “How we Rooted Copilot” describes obtaining root access inside a Jupyter container. Root privileges inside that container are serious, but they do not by themselves demonstrate a break out to the host or compromise of the wider service. The account does not establish how broadly its demonstration applies across product versions or configurations.

For people deploying command-capable assistants, the practical boundary to examine is the permission granted to tools: what commands they can run, what files and credentials they can read, and whether actions require confirmation. A successful demonstration in one environment is a reason to examine those controls, not proof that every deployment has the same exposure.

A reported bank intrusion used a small device and process hiding

Hackaday’s roundup described an intrusion into a bank network involving a Raspberry Pi fitted with a 4G cellular modem. It attributed the activity to UNC2891 and said the suspected objective involved the bank’s ATM network and hardware security module. The roundup also described a Linux technique that used bind mounts to hide malicious processes under /proc. These details are the roundup’s account of the incident; the linked technical report was not independently available for verification here. The exact Raspberry Pi model and modem are not established.

The device matters in this story as reported intrusion hardware, not as a recommended home-security project. The broader lesson is that a device with an outside network connection can provide an attacker with a foothold that does not depend on the organization’s usual internet-facing entry points.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A CSRF and CORS chain reached a cloud-identity capability

Zero-Defense’s penetration-test account describes chaining cross-site request forgery (CSRF) with a cross-origin resource sharing (CORS) misconfiguration. According to the report, the chain reached an SSH key-generation utility and exposed cloud identity access at an unnamed startup building a zero-trust, VPN-like access platform.

This is an account of one engagement, not evidence that zero-trust products as a class are ineffective. It illustrates why controls that govern browser-origin requests and downstream identity access still matter in systems built around a zero-trust model.

The Nvidia H20 story was an allegation, not a verified backdoor

Hackaday reported that Chinese officials accused Nvidia of putting a backdoor in its H20 GPU and described the matter as unclear. The linked Ars Technica report was not available for independent verification here, and no later technical evidence or official outcome is established by the material available for this roundup. The claim should therefore be described as an allegation; the cited account does not establish either that a backdoor existed or that the accusation was disproved.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Other items: analysis tooling, a CrushFTP RCE report and a CRM exposure

CISA’s Thorium platform

CISA’s Thorium repository describes a scalable file-analysis and data-generation platform for coordinating tools. It is a security-analysis platform, rather than a reported breach in this roundup.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CrushFTP remote code execution

The roundup linked a CrushFTP remote-code-execution report. The material available for this historical item does not establish the affected-version range or current patch status, so it should not be used on its own as a present-day vulnerability advisory.

CRM user records returned through a changed HTTP method

An Infosec Writeups account described a CRM endpoint returning user records when queried using a different HTTP method. The CRM vendor is unnamed in the available account, which also does not establish the system’s current remediation status.

How to read the incidents without conflating them

These stories are not equivalent measures of risk. A useful comparison asks what boundary was crossed and what kind of evidence supports the claim:

  • Confirmed or reported exposure: the Tea and GiveWP items describe personal information made accessible; their scope and the source of each detail still need to be attributed carefully.
  • Security-research demonstrations: the AI and CSRF/CORS reports describe paths demonstrated in particular tools or engagements. Their results do not automatically generalize to every product or deployment.
  • Incident reporting with qualified attribution: the bank intrusion account includes operational details, but those details remain attributed to Hackaday here.
  • Unresolved allegation: the H20 claim is not established as a hardware backdoor by the cited account.

The roundup was published on August 1, 2025. It is a record of those stories at that time, not a current assessment of vulnerability fixes, product versions or the later outcome of the H20 accusation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.