Vulnerability Management, Data Security

Data-leaking Carlsberg event wristband remains unremediated

Adobe Stock

Danish multinational brewing company Carlsberg Group has yet to address a high-severity security vulnerability impacting wristbands it provided in a Copenhagen-based exhibition months after the flaw was flagged by Pen Test Partners researcher Alan Monie to have exposed attendees' personally identifiable information, reports HackRead.

Included with every wristband is a QR code redirecting to a personalized "memories" page containing individuals' names, IDs, photos, and videos, which could be accessible through a basic script, according to Monie, who discovered that brute-force enumeration remained possible months after he reported the issue through Zerocopter, the brewery's official disclosure platform. While Zerocopter barred the release of a report on the vulnerability, Pen Test Partners went ahead to publicize the bug after over five months of silence from Carlsberg.

Such a development comes weeks after Pen Test Partners was accused of blackmail by Western European high-speed rail service operator Eurostar, following their disclosure of critical flaws in the firm's AI chatbot.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds