ADVERTISEMENT

Muted Applause: leading software testing firm leaves credentials vulnerable

Applause, a leading software testing company, inadvertently left its credentials open to unauthorized visitors, allowing attackers to make a move for customer data.

Applause research

Image by Cybernews.

Ernestas Naprys
Ernestas Naprys Senior Journalist
August 28, 2024 Updated: August 29, 2024 2 min read
applause-leak
ADVERTISEMENT

Customer data could be exposed

  • Credentials from Marketo, a marketing automation platform. A potential attacker could use these to gain access to marketing data, email campaigns, and customer interactions. The data can be further exploited in phishing attacks, spam, and exposure of sensitive data.
  • SalesForce credentials, which provide full access to the platform. Unauthorized attackers could use them to steal data, approve transactions, and manipulate customer data, leading to significant financial loss and reputational damage. Additionally, attackers could use this data for targeted phishing attacks against Applause’s clients.
  • Gotowebinar account credentials, exposing webinar schedules, participant data, and recordings. With these, an attacker could disrupt scheduled events, obtain participant information, and misuse recordings, leading to privacy breaches and disruption of business operations.
  • WordPress Rocket credentials. WP Rocket is a popular content caching and performance optimization plugin. If compromised, attackers potentially degrade website performance or inject malicious content, disable caching, and manipulate other settings, leading to increased server load, slower page load times, and a worse user experience.
  • Location of the WordPress debug log, a diagnostic tool used to troubleshoot issues on a website. The log can reveal detailed error messages, system paths, and other useful information to attackers looking for potential vulnerabilities and misconfigurations. This information can be used to launch further attacks.
  • Investigate access logs to identify whether any threat actors have accessed the exposed sensitive information.
  • Rotate all exposed credentials to mitigate current risks.
  • Implement stricter access controls, use environment-specific configurations, and encrypt sensitive data at rest and in transit.
  • Inform affected users and regulators if needed.
ADVERTISEMENT