An unprotected server has exposed more than 7GB of data from the beauty brand.
A research team at SafetyDetectives has discovered an unprotected server for direct-sales beauty company Avon and found more than 7GB of data, including more than 19 million records, open and available with no authorization required.
The information on the server included both critical details about individuals and administrative data, such as OAuth tokens and administrative user names. Between the two types of data, attackers could conduct extensive identity theft operations and gain access to significant administrative capabilities on the server.
According to the researchers, around the time of their discovery in early June, Avon issued a pair of statements indicating that a data breach had occurred and was being remediated as systems were restarted. Avon noted that no financial data was involved in the breach because that data was not stored on the server involved.
Read more here.
About the Author(s)
You May Also Like
Guarding the Cloud: Top 5 Cloud Security Hacks and How You Can Avoid Them
April 4, 2024Cybersecurity Strategies for Small and Med Sized Businesses
April 11, 2024Defending Against Today's Threat Landscape with MDR
April 18, 2024Securing Code in the Age of AI
April 24, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024Black Hat Asia - April 16-19 - Learn More
April 16, 2024