In December ASPEN set their sights on McDonald’s, and we cooked up an interesting menu of vulnerabilities. What we found was a major security lapse in the McDelivery system for McDonald’s India (West & South), exposing sensitive customer and driver data. ASPEN researcher Eaton Zveare uncovered API flaws that allowed unauthorized access to personal details, real-time order tracking, and even the ability to place $0.01 orders. These vulnerabilities, which could have impacted millions, highlight the dangers of weak API security in modern food delivery services.
Join us as we break down these exploits, discuss the technical oversights that led to them, and the methodology used to find them. Whether you’re a security professional, developer, this session will serve up valuable insights into securing critical online services before attackers take a bite.
The ASPEN eyJ Webinar Series is a monthly deep dive into the latest in API and application security, designed for security practitioners by security practitioners. No fluff, no marketing—just pure technical insights.
Each month, we’ll cover:
This is not just another webinar—it’s an interactive experience. Bring your questions, engage in live discussions, and be part of a security community that values real, actionable insights.