Researcher buys noreply.net domain, lands companies' confidential emails
A security researcher purchased the expired domain noreply.net, which many companies use as a sender address for automated emails without verifying ownership. As a result, the researcher now receives sensitive internal information and secrets sent by those companies to other parties. The incident exposes a widespread flaw in how organizations configure email systems.
Sources (1)
technology