Top stories.
- Popular AI app exposes millions of users' chat messages.
- White House rescinds Biden-era software security rules.
- Ivanti fixes two critical zero-days.
Popular AI app exposes millions of users' chat messages.
Chat & Ask AI, one of the top AI apps in the Google Play and Apple App stores, exposed hundreds of millions of users’ private messages with the chatbot, 404 Media reports. An independent researcher found "a misconfiguration in the app’s usage of the mobile app development platform Google Firebase, which by default makes it easy for anyone to make themselves an 'authenticated' user who can access the app’s backend storage where in many instances user data is stored." The researcher was able to access 300 million messages from more than 25 million users, including extremely sensitive information that users discussed with the chatbot.
Codeway, the Turkish developer of Chat & Ask AI, fixed the issue within hours after the researcher disclosed the flaw. The company hasn't responded to 404 Media's request for a comment.

