Danish multinational brewing company Carlsberg Group has yet to address a high-severity security vulnerability impacting wristbands it provided in a Copenhagen-based exhibition months after the flaw was flagged by Pen Test Partners researcher Alan Monie to have exposed attendees' personally identifiable information, reports HackRead.Included with every wristband is a QR code redirecting to a personalized "memories" page containing individuals' names, IDs, photos, and videos, which could be accessible through a basic script, according to Monie, who discovered that brute-force enumeration remained possible months after he reported the issue through Zerocopter, the brewery's official disclosure platform. While Zerocopter barred the release of a report on the vulnerability, Pen Test Partners went ahead to publicize the bug after over five months of silence from Carlsberg.Such a development comes weeks after Pen Test Partners was accused of blackmail by Western European high-speed rail service operator Eurostar, following their disclosure of critical flaws in the firm's AI chatbot.
Vulnerability Management, Data Security
Data-leaking Carlsberg event wristband remains unremediated

Adobe Stock
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



