Explore Problems
Showing 2,982 of 9,941 problems · matching your filters
30-Day Forgery Notice Rules Deny Elder Financial Fraud Claims
When an elderly or incapacitated account holder is defrauded via forged checks over an extended hospitalization, banks can deny the resulting fraud claim by citing a 30-day statement-review window that the victim's family had no realistic way to meet. This structural rule shifts liability for extended-pattern forgery onto vulnerable account holders rather than the bank, even after a police report and formal dispute are filed.
Credit Bureau FCRA Violations Leave Inaccurate Data on Reports
Major credit bureaus like TransUnion routinely violate the Fair Credit Reporting Act by maintaining inaccurate data, failing to investigate disputes properly, and not correcting errors within statutory timelines. These violations directly impair consumers' access to credit, housing, and employment. Automated FCRA violation documentation and regulatory complaint filing tools could significantly improve consumers' enforcement leverage.
Prepaid Card Users Face Unauthorized Charges With No Support Response
Prepaid card holders report unauthorized charges draining their balances, compounded by customer support that is entirely unreachable by phone or email. This leaves users unable to recover funds or resolve fraud disputes, undermining trust in prepaid financial products.
Credit card accounts opened without customer consent or knowledge
Consumers discover new credit lines opened in their name without authorization, and the issuing bank's customer service declines to investigate or resolve the fraud, instead directing victims to deal with the perpetrator directly. This leaves affected consumers without institutional recourse for unauthorized account openings.
npm Ecosystem Silently Executes Malicious Code via Transitive Dependencies
Every npm install is an implicit trust decision across hundreds of packages, any of which can execute arbitrary code via postinstall hooks with no user confirmation. The Axios backdoor attack demonstrated this at 80M weekly download scale, with sophisticated obfuscation and self-cleanup. Existing tools like Snyk detect known vulnerabilities but do not prevent silent postinstall execution from newly compromised accounts.
Banking apps show transactions but provide no actionable spending intelligence
Most banking and personal finance apps display raw transaction lists without analyzing patterns, trends, or behavioral insights. Users cannot identify where their money actually goes without manual categorization in separate tools. The gap between data display and financial intelligence leaves the majority of banking customers without practical guidance.
Salesforce Is Too Complex and Expensive for Small Business Users
Salesforce Sales Cloud is widely criticized for overwhelming complexity, long setup times, and high licensing costs that are prohibitive for small businesses. The interface feels cluttered and requires significant expertise to customize, creating a large gap between enterprise capability and usability. This drives persistent demand for simpler CRM alternatives.
Malicious VSCode Extensions Can Breach Thousands of GitHub Repositories
A single malicious VSCode extension compromised 3,800 GitHub repositories, exposing a critical gap in extension marketplace security vetting. The extension marketplace provides no meaningful safety signals, leaving developers unable to assess extension trustworthiness at install time.
MCP Servers Inject Context Tokens on Every Message Even When Not Used
Every configured MCP server injects tokens into the context window on each message, regardless of whether that server is needed for the current task. As developers add more MCP servers, context window bloat becomes severe and reduces effective model capacity. No selective MCP loading mechanism exists to activate servers only when relevant.
Cloud AI Coding Agents Require Sharing Codebases; Local Models Lack Performance
Developers using cloud-based AI coding agents like Cursor, Codex, or Claude must expose their codebase to training pipelines. Switching to local models for privacy eliminates the performance needed for real coding tasks. No tool currently solves both privacy and performance simultaneously.
Indian Personal Finance Apps Mandate Bank Linking or SMS Scraping to Build Credit Profiles
Every major personal finance app in India forces users to link bank accounts via Account Aggregator or grant SMS access, then ships data to remote servers for credit profiling and loan marketing. Users who want privacy-respecting expense tracking have no viable alternative.
Banks Freeze Large Accounts on Fraud Suspicion With No Access or Explanation
Bank customers describe accounts holding tens of thousands of dollars frozen indefinitely after an automated fraud flag, with no written notice and no channel to get funds released. Weeks of phone calls yield only verbal updates, leaving people without access to money they depend on.
AI Support Chatbots Hallucinate and Refuse to Escalate to Humans
AI chatbots like Intercom Fin generate responses outside their configured knowledge base and fail to hand off to human agents when users explicitly request it. This erodes customer trust and creates liability for businesses relying on AI-first support. The problem is structural across AI support tools, not limited to any single vendor.
Air-Gapped Networks Have No Passive Threat Detection Without Active Scanning Risk
Security teams protecting air-gapped environments — defense, ICS, nuclear — cannot use conventional network detection tools that require active probes, which risk triggering false alerts or disrupting critical operations. Passive monitoring that can identify C2 beacons and DNS generation algorithm traffic without sending any packets is absent from the market. This leaves some of the highest-value targets with a fundamental detection blind spot.
Credit Reports Showing Accounts That Belong to Someone Else
Consumers frequently find unfamiliar accounts or inquiries on their credit reports that they never authorized and that belong to another person, often due to identity theft or mixed credit files. This is one of the highest-volume categories of credit bureau complaints, and existing dispute processes are slow to resolve it.
Phone Theft Enables Immediate High-Value Zelle and Venmo Fraud Banks Refuse to Refund
Thieves who steal unlocked phones can immediately execute thousands of dollars in Zelle and Venmo transfers before the owner can react. Payment apps treat physical phone possession as sufficient authorization, creating a structural gap where theft of a device equals theft of funds. Banks and payment platforms systematically deny fraud refunds for these transactions because the device was used directly.
Zelle Transfers to Wrong Recipient Cannot Be Recalled by Banks
A single digit error when entering a Zelle recipient phone number sends funds to the wrong person with no recovery path — banks disclaim liability and Zelle has no recall mechanism for voluntary transactions. With hundreds of millions of Zelle transactions per year, the scale of accidental misdirection is enormous. Pre-send recipient identity confirmation and rapid escalation tools for same-day misdirection cases would address a structural gap.
Bank ACH Dispute Delays Risk Homeowners' Liens and Foreclosure Threats
Consumers who make ACH payments that banks fail to properly process face month-long dispute resolution timelines with no interim protection, even when a missed payment triggers collection agency action and a threatened property lien. The bank's slow, opaque investigation process leaves account holders unable to prove payment was made, risking severe consequences like losing their home.
Bank security alert systems fail to fire during active account takeover via phishing
Customers who configure bank security alerts for new device logins and failed password attempts receive no notifications when fraudsters are actively taking over their accounts via phishing. Alert systems that customers rely on as a safety net fail silently at exactly the moment they are needed. The combination of caller ID spoofing and alert failure gives attackers undetected access windows long enough to drain accounts.
Salesforce Locks Essential CRM Features Behind Expensive Add-On Tiers
Salesforce's pricing model places many of its most valuable features in premium add-on tiers, making the true cost of a functional deployment far higher than base plan pricing suggests. This tiered gating disproportionately affects mid-market companies that need advanced capabilities but cannot justify enterprise pricing. The practice has driven sustained interest in CRM alternatives with more transparent feature bundling.