Australia has a massive cyber security problem
I discovered vulnerabilities on NDIS service provider websites. Which leaks personally identifiable information about patients, employeers, suppliers, their addresses, first and last name, etc
I reported the vulnerability to the NDIS provider in Feb 2022, March 2022, June 2022. I reported the vulnerability to Australian Signals Directorate's ACSC in 2022. I reported the vulnerability to to
Cyber.gov.au followed all the correct procedures
I checked the URL today and guess what? It's still leaking personal data: 4 years later. The vulnerability is still live. You can still see peoples personally identifiable information from a misformed URL.
It's publicly available. To anyone right now.
I have seen many such cases. But this is the most egregious.