Patrick Quirk

Four Platforms, Zero Responses, 75 Days

A researcher disclosed security vulnerabilities across four conservative media platforms in March. All four ignored the disclosure. Three eventually patched without responding. One did nothing at all.

Patrick Quirk's avatar
Patrick Quirk
Jun 18, 2026
∙ Paid

How This Started

In late March 2026, security researcher @weezerosint documented security vulnerabilities across four platforms: tuckercarlson.com, Valuetainment, Minnect, and Newsmax/Banned.Video. A friend forwarded the thread and asked whether any of it checked out.

It checked out. All of it.

What followed was independent verification, three re-verification passes over 75 days, and a disclosure process that generated zero acknowledgments from any of the four vendors.

Here is the current status of each platform, verified June 10, 2026.


Tucker Carlson: 7,290 Real Users, 56.8 Million Claimed

tuckercarlson.com was built on Supabase with Row Level Security disabled. The anonymous API key was embedded in the page source, readable by anyone who opened browser devtools. With that key and the Supabase client library, anyone could query the database directly.

What the database contained:

  • 7,290 subscriber profiles

  • 15,960 chat messages

  • Usernames, message content, and AI moderation flags per account

The platform patched the exposure after @weezerosint published the findings publicly on April 28, 2026. The private disclosure, sent March 27, generated no response. The public tweet did.

The 56.8 million figure on Tucker Carlson Network’s own infographic is not a subscriber count. The fine print reads “Average Episode Views Across Socials + Podcast Platforms.” That number aggregates every view across YouTube, X, Spotify, Apple Podcasts, and every other platform where the content appears, counting one person watching ten episodes as ten viewers. It is then placed on the same chart as Fox News’s 3.2 million concurrent primetime viewers as though the numbers are comparable.

The actual platform, tuckercarlson.com, had 7,290 registered users at the time of disclosure. That number was verifiable with a single unauthenticated HTTP request before the patch.


Valuetainment: 75,003 Member Emails Still in Google’s Index

Valuetainment uses AIOSEO Pro to generate XML sitemaps for BuddyPress member profiles. The profile URLs encode email addresses directly in the slug. A member with the email john.smith@gmail.com gets a URL that looks like:

https://valuetainment.com/members/johnsmithgmail-com/

Those slugs are spread across 76 public XML files, all returning HTTP 200, all actively crawled by Google. Approximately 63% decode to readable email addresses.

As of this morning:

  • 76 sitemap pages, all live, no authentication required

  • Approximately 75,003 member slugs, up from 74,962 at original disclosure

  • Growth rate: roughly one new member per day, added to the public index automatically

  • Zero slugs removed in 75 days

  • Zero patches applied

The platform’s REST API (/wp-json/wp/v2/users) was gated at some point before May 2026. That partial fix left the sitemaps, which expose the same data through a different path, completely untouched.

To verify yourself, open a browser and go to:

https://valuetainment.com/bp-member-sitemap1.xml

No login. No tools. One URL.


Minnect: Staff Accounts, Expert UUIDs, and a Paywalled Response

Minnect’s WordPress site (www.minnect.com) serves nine registered staff accounts from its unauthenticated REST endpoint. Each record includes a login slug encoding a work email address and a Gravatar SHA-256 hash tied to that address. That endpoint returned HTTP 200 with all nine accounts intact this morning.

The main expert API (api.minnect.com/api/v2/experts) requires no authentication and returns 1,268 expert records including internal UUIDs and SendBird direct-message channel IDs. Patrick Bet-David, Polet Bet-David, and Jennifer Bet-David are in the directory with their UUIDs and DM channel identifiers returned to any unauthenticated caller.

The original disclosure also described a separate endpoint at /api/v2/users returning 290,000 user records including home street addresses, city, state, zip, and country. That endpoint now returns HTTP 401. Every other path on the API returns 404, confirming the route exists but has been gated. No acknowledgment, no notification to affected users. A silent patch, same as the others.

I reached out to a Minnect staff member on LinkedIn to discuss the disclosure. Their response was to message them on Minnect. Minnect is a paid platform: it charges users to send messages to experts. The platform’s own unauthenticated API hands out the internal SendBird DM channel ID for every expert at no cost, but actually sending a message through it costs money.


Newsmax: Patched, But Someone Got There First

Newsmax silently patched the PII endpoint after the disclosure. No response to the original email, the follow-up, or the deadline notice.

What @weezerosint documented before the patch is more significant than the patch itself: the Newsmax ceo@ and info@ email accounts in the exposed endpoint had been defaced before he found them. Someone else discovered the endpoint first. That was not a security researcher. That was a breach. Newsmax’s security team either did not notice or did not care. The platform patched the door after someone had already walked through it and rearranged the furniture.


Banned.Video: IP Field Removed, Viewing History Unconfirmed

Banned.Video silently removed an exposed IP field that was part of the original disclosure. The platform also exposed individual user viewing histories per @weezerosint’s original findings. That endpoint was not independently re-verified in this pass. The current status of the viewing history exposure is unconfirmed.

Neither the IP field removal nor any other remediation was acknowledged by the platform.


Scoreboard

  • Tucker Carlson: patched after public tweet, not after private disclosure, zero response

  • Valuetainment: unpatched, still live, still growing

  • Minnect: WP REST and expert API unpatched; 290K address endpoint silently gated (401), no acknowledgment

  • Newsmax: patched, accounts defaced before patch, zero response

  • Banned.Video: IP field removed, viewing history endpoint status unconfirmed, zero response

Zero responses from any of the four vendors across 75 days.


The Timeline

  • 2026-03-27 to 28: Full disclosure sent to all four platforms by @weezerosint

  • 2026-04-04: Follow-up emails with deadlines

  • 2026-04-28: 32 days in, zero responses; @weezerosint publishes findings publicly; Newsmax and Banned.Video confirmed silently patched

  • 2026-04-30: Tucker Carlson patches Supabase exposure after public tweet

  • 2026-05-01: Independent re-verification; Valuetainment and Minnect confirmed live

  • 2026-05-12: Second re-verification; 74,972 Valuetainment members; Minnect WordPress REST surface documented; Koombea contractor identified

  • 2026-06-10: Third re-verification; ~75,003 Valuetainment members; Minnect WP REST unchanged; Tucker Carlson patched confirmed


What Still Needs to Happen

Valuetainment: Disable BuddyPress sitemaps in AIOSEO Pro. Dashboard > Sitemaps > BuddyPress, toggle off member and activity sitemaps. 60 seconds.

Minnect: Add authentication to /wp-json/wp/v2/users. Require auth on /api/v2/experts. Audit the SendBird app token scope. Locate and gate the original 290K address endpoint if it still exists.

Banned.Video: Audit remaining API routes for viewing history data. Confirm the viewing history endpoint is actually closed.

User's avatar

Continue reading this post for free, courtesy of Patrick Quirk.

Or purchase a paid subscription.
© 2026 Ringmast4r · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture