IoT Vendor Orvibo
Internet of things (IoT) vendor Orvibo leaked billions of user records via an exposed and unsecured ElasticSearch server. Orvibo runs the smart appliance platform SmartMate, used to manage a modern smart home. The exposed data includes logins, password resets, device heartbeats, logouts, customer email addresses, device IP addresses, usernames, and MD5-hashed passwords. A threat actor could use password reset codes to lock users out of their accounts. The security team at vpnMentor discovered the misconfigured server a few weeks ago and have attempted to contact Orvibo; however, the company has yet to respond or secure the server. More information can be found in the Forbes article.