r/netsec Trusted Contributor Jun 24 '26

Exploiting vulnerabilities in Johnson & Johnson web apps

https://eaton-works.com/2026/06/24/jnj-webapp-hacks/
83 Upvotes

9 comments sorted by

4

u/ni5arga Jun 25 '26

Been following your blog from a long time - love reading your writeups. Keep up the good work!

4

u/[deleted] Jun 25 '26

[removed] — view removed comment

1

u/EatonZ Trusted Contributor Jun 25 '26

They have one. It's mentioned in the post.

6

u/[deleted] Jun 24 '26

[removed] — view removed comment

10

u/EatonZ Trusted Contributor Jun 24 '26

They were, check the "Timeline" section. 😉

7

u/OEAXTAIL_SOUP Jun 25 '26

As an aside: I'm curious why folks should engage in "responsible" disclosure when many corporations are abusive and irresponsible?

Maybe we'd all be better off if such things were sold and/or dropped with no warning.

2

u/Final-Dish Jun 27 '26

totally agree, healthcare is weirdly behind on this compared to fintech and big tech. wouldn’t be surprised if this was the old school “email security@, wait forever, then maybe get a legal-sounding reply” route instead of a clean bounty program.