Cloud Security Carla car rental data exposed in unsecured AWS bucket July 22, 2026 Share By SC Staff (Adobe Stock) Coverage from Tech Radar indicates that the car rental comparison and booking platform Carla had a database containing sensitive customer information exposed on the open internet. Cybersecurity researchers from Cybernews discovered an unsecured Amazon Web Services (AWS) bucket containing approximately 48,000 PDF files with customer rental data. The exposed files, identified as belonging to Carla, contained personal information of drivers including names, email addresses, phone numbers, rental details, confirmation numbers, and travel patterns. Cybernews noted that this data could be exploited for sophisticated phishing attacks, using travel patterns to build trust with victims. After being notified, Carla secured the database. While there is currently no evidence of malicious access, the risk remains as automated tools could have discovered the unsecured data. This incident highlights the ongoing issue of misconfigured databases and the importance of understanding cloud security responsibilities. Cybernews also recently reported a similar exposure involving Nextcloud, which leaked employee and client data. Source: Tech Radar An In-Depth Guide to Cloud Security Get essential knowledge and practical strategies to fortify your cloud security. Learn More SC Staff Related Identity SharePoint vulnerability steals machine keys; fourth recent exploit Steve Zurier July 22, 2026 New SharePoint flaw exploited as attackers steal machine keys for lasting access. Cloud Security Critical ServiceNow AI flaw exploited days after patch release Steve Zurier July 20, 2026 Attackers exploit critical ServiceNow AI bug just days after security patch release. Cloud Security Google Mandiant warns of exposed serverless functions as attack vector SC Staff July 16, 2026 Mandiant has observed an increase in public-facing serverless applications lacking authentication, often due to business needs. Related Events Cybercast From prompt to exploit: How LLMs are changing API attacks Mon Jul 27 Cybercast Cloud Security: The AI Effect and How to Proceed On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Cloud Computing Greynet You can skip this ad in 5 seconds