Security researcher Chris Vickery found a misconfigured MongoDB database for Microsoft Careers. The database for the mobile version of Microsofts Careers site was exposed to the open Internet and required no authentication at all to access. Vickery sent an email to Microsoft which contained a screenshot showing the name, email address, password hash, and issued tokens for Microsoft’s Global Employment Brand Marketing Manager, Karrie Shepro. The good news is that it took only about an hour to Microsoft to lock down the database.”]

