<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Insecure-Logging — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/insecure-logging/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 23 Mar 2026 14:00:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/insecure-logging/feed.xml" rel="self" type="application/rss+xml"/><item><title>EquityPandit 1.0 Insecure Logging Vulnerability (CVE-2019-25605)</title><link>https://feed.craftedsignal.io/briefs/2026-03-equitypandit-logging/</link><pubDate>Mon, 23 Mar 2026 14:00:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-03-equitypandit-logging/</guid><description>EquityPandit 1.0 contains an insecure logging vulnerability (CVE-2019-25605) that allows attackers to capture sensitive user credentials by accessing developer console logs via Android Debug Bridge, specifically exposing plaintext passwords during the forgot password function.</description><content:encoded>&lt;p>EquityPandit 1.0, an Android application, is vulnerable to insecure logging practices. Specifically, the application logs sensitive user credentials, including plaintext passwords, within the developer console logs. This vulnerability, identified as CVE-2019-25605, allows an attacker with access to the device or ADB (Android Debug Bridge) to extract these credentials. The vulnerability was reported in 2019, but publicly disclosed details and exploits surfaced more recently. Successful…&lt;/p>
</content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>insecure-logging</category><category>credential-access</category><category>android</category></item></channel></rss>