The affected infrastructure is called GSPIMS and is a web application that allows employees and suppliers to manage the supply chain globally. A researcher, who wishes to remain anonymous, has discovered a backdoor in these systems that allows access to the portal with, simply, an email account.

En sus pruebas, The investigator has managed to access numerous confidential documents, internal projects, supplier data and more critical information. Toyota, for its part, confirms that they solved this last 23 November.

The worrying thing about the matter is that a malicious actor could have accessed critical Toyota information and copied the information without altering it.

Fountain: Bleeping Computer


Leave a Reply

Your email address will not be published. Required fields are marked *

More news
This is how the use of AI in cybercrime has evolved
Read more »
Skoda confirms a breach on its web portal
Read more »
data of almost 200.000 Zara users are exposed
Read more »
Vimeo sufre una brecha de datos
Read more »
Booking.com suffers a data exfiltration of bookings
Read more »