Signed up for Klaviyo? Dozens of advertisers may have seen your password

https://techcrunch.com/wp-content/uploads/2026/08/klaviyo-2283003642.jpg?resize=1200,800

Newly revealed security research found that until recently, marketing tech giant Klaviyo was inadvertently sharing the sign-up information of its new customers, including their passwords, with outside advertisers.

Sam Jadali, a security researcher and co-founder of cybersecurity startup Melurna, told TechCrunch that the web form on Klaviyo’s sign-up page was misconfigured between at least February 2024 through November 2025, though likely longer.

The startup’s tests found that anyone who signed up to Klaviyo using the misconfigured form may have had their sign-up information shared with any of the third-party tech giants and advertisers whose trackers are also embedded on the company’s website.

This sign-up data included the customer’s email address and password, as well as their company’s name, website address, and phone number. This information was shared with advertising and tech giants including Facebook and Google; marketing giant HubSpot; Microsoft and its subsidiary LinkedIn; social media site X, and...

Copyright of this story solely belongs to techcrunch.com. To see the full text click HERE

Read more

https://cdn.mos.cms.futurecdn.net/RQ5KTXE36KotRhswGqamze-1920-80.jpg

I thought asking an AI agent to book a gym class was harmless, then I saw what happened if you ask Claude and OpenClaw to ‘move me to the top of the list’ — now I’m adding one safeguard to every agent prompt

AI agents seem to be getting a little out of control lately. Within the last few weeks, agents from OpenAI and Anthropic have been reported doing whatever it took to achieve their goal, while other incidents involved agents escaping sandboxed environments and hacking into companies Now another concerning incident has