Sign up for our daily briefing

Make your busy days simpler with Axios AM/PM. Catch up on what's new and why it matters in just 5 minutes.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Denver news in your inbox

Catch up on the most important stories affecting your hometown with Axios Denver

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Des Moines news in your inbox

Catch up on the most important stories affecting your hometown with Axios Des Moines

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Minneapolis-St. Paul news in your inbox

Catch up on the most important stories affecting your hometown with Axios Twin Cities

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Tampa Bay news in your inbox

Catch up on the most important stories affecting your hometown with Axios Tampa Bay

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Charlotte news in your inbox

Catch up on the most important stories affecting your hometown with Axios Charlotte

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Photo: Westend61 via Getty Images

A database containing millions of text messages used to authenticate users signing into websites was left exposed to the internet without a password, TechCrunch's Zack Whittaker reports.

Why it matters: What was at risk here were those text messages a bank might send customers after they entered a passwords, password reset links and other automated text messages sent by businesses. While there's no evidence that a malicious actor was monitoring the database, it was dangerous information to have exposed.

Details: The database belonged to the automated text message service Voxox. Per the report:

  • The database was discovered by security researcher Sébastien Kaul and remained online until Whittaker contacted Voxox.
  • The text messages included security codes sent by Fidelity Investments, Booking.com and Google.
  • Voxox had sent more than 26 million text messages to date this year.

But, but, but: Remember, these codes typically only remain active for a few minutes. So while the danger would be very real, only text messages that were being monitored as they were added to the database would put anyone's account at risk.

Go deeper

The new Washington

Illustration: Sarah Grillo/Axios

The Axios subject-matter experts brief you on the incoming administration's plans and team.

Rep. Lou Correa tests positive for COVID-19

Lou Correa. Photo: Tom Williams/CQ-Roll Call, Inc via Getty Images

Rep. Lou Correa (D-Calif.) announced on Saturday that he has tested positive for the coronavirus.

Why it matters: Correa is the latest Democratic lawmaker to share his positive test results after last week's deadly Capitol riot. Correa did not shelter in the designated safe zone with his congressional colleagues during the siege, per a spokesperson, instead staying outside to help Capitol Police.

Far-right figure "Baked Alaska" arrested for involvement in Capitol siege

Photo: Shay Horse/NurPhoto via Getty Images

The FBI arrested far-right media figure Tim Gionet, known as "Baked Alaska," on Saturday for his involvement in last week's Capitol riot, according to a statement of facts filed in the U.S. District Court in the District of Columbia.

The state of play: Gionet was arrested in Houston on charges related to disorderly or disruptive conduct on the Capitol grounds or in any of the Capitol buildings with the intent to impede, disrupt, or disturb the orderly conduct of a session, per AP.