Avon Server Leaks User Info and Administrative DataAvon Server Leaks User Info and Administrative Data
An unprotected server has exposed more than 7GB of data from the beauty brand.
July 29, 2020
A research team at SafetyDetectives has discovered an unprotected server for direct-sales beauty company Avon and found more than 7GB of data, including more than 19 million records, open and available with no authorization required.
The information on the server included both critical details about individuals and administrative data, such as OAuth tokens and administrative user names. Between the two types of data, attackers could conduct extensive identity theft operations and gain access to significant administrative capabilities on the server.
According to the researchers, around the time of their discovery in early June, Avon issued a pair of statements indicating that a data breach had occurred and was being remediated as systems were restarted. Avon noted that no financial data was involved in the breach because that data was not stored on the server involved.
Read more here.
About the Author(s)
Tricks to Boost Your Threat Hunting GameNov 06, 2023
Hacking Your Digital Identity: How Cybercriminals Can and Will Get Around Your Authentication MethodsOct 26, 2023
Modern Supply Chain Security: Integrated, Interconnected, and Context-DrivenNov 06, 2023
How to Combat the Latest Cloud Security ThreatsNov 06, 2023
Reducing Cyber Risk in Enterprise Email Systems: It's Not Just Spam and PhishingNov 01, 2023
Passwords Are Passe: Next Gen Authentication Addresses Today's Threats
How to Deploy Zero Trust for Remote Workforce Security
Everything You Need to Know About DNS Attacks
Securing the Remote Worker: How to Mitigate Off-Site Cyberattacks
How Enterprises Are Managing Application Security Risks in a Heightened Threat Environment
9 Traits You Need to Succeed as a Cybersecurity Leader
The Ultimate Guide to the CISSP
Gone Phishing: How to Defend Against Persistent Phishing Attempts Targeting Your Organization
Building Immunity: The 2021 Healthcare and Pharmaceutical Industry Cyber Threat Landscape Report
Build a Case for a Password Manager