Original Release Date: 7/8/2019
Internet of things (IoT) vendor Orvibo leaked billions of user records via an exposed and unsecured ElasticSearch server. Orvibo runs the smart appliance platform SmartMate, used to manage a modern smart home. The exposed data includes logins, password resets, device heartbeats, logouts, customer email addresses, device IP addresses, usernames, and MD5-hashed passwords. A threat actor could use password reset codes to lock users out of their accounts. The security team at vpnMentor discovered the misconfigured server a few weeks ago and have attempted to contact Orvibo; however, the company has yet to respond or secure the server. More information can be found in the Forbes article.