Cybernews AI-Assisted Ticketing Exploit Exposes Major US Music Festivals
Article Content
- •A critical SQL injection vulnerability in Front Gate Tickets allowed full administrative access.
- •Ian Carroll used Claude AI to exploit the vulnerability, potentially issuing unlimited tickets.
- •The flaw could expose sensitive customer data and internal credentials across the platform.
Ian Carroll, a security researcher, exploited an unauthenticated SQL injection vulnerability in Front Gate Tickets, a subsidiary of Live Nation, with assistance from Anthropic's Claude AI. This flaw allowed him to gain administrative access to the ticketing platform, potentially issuing unlimited tickets for major US music festivals, including Bonnaroo and Electric Daisy Carnival. The vulnerability stemmed from improper input sanitization in the device API, enabling Carroll to bypass the site's web application firewall. He discovered sensitive data, including employee login information and password reset tokens, but did not redeem any tickets. The incident raises significant concerns about the security of ticketing systems for large events. The vulnerability could allow malicious actors to access customer records and issue complimentary tickets. The researcher reported the issue without exploiting it further.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track ShinyHunters and Front Gate Tickets in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
ShinyHunters Hack Exposes Sensitive FBI Employee Data On September 23, 2026, the FBI disclosed an investigation into a data breach by the hacking group ShinyHunters, which claims to have stolen sensitive personal information of approximately 38,000 FBI employees and job applicants. The stolen data reportedly includes names, addresses, phone numbers, Social Security…
ShinyHunters Escalate Oracle PeopleSoft Exploitation Amid Microsoft Mega-Patch ShinyHunters, a hacking group, has escalated attacks exploiting Oracle PeopleSoft vulnerability CVE-2026-35273 following the arrest of a member in the Netherlands. This vulnerability, with a CVSS score of 9.8, is being exploited using URL-encoding techniques to bypass web application firewalls. Microsoft recently…