Estée Lauder breached via Oracle E-Business Suite flaw
Cosmetics giant notifies customers after attackers exploited vulnerability in HR system, exposing employee and customer data through enterprise software weakness.
Estée Lauder is notifying customers of a data breach stemming from a vulnerability in Oracle E-Business Suite, the enterprise resource planning platform the company used for human resources operations.
The breach exposed personal information of both employees and customers. Attackers exploited a known flaw in the Oracle software to gain unauthorized access to systems containing sensitive data. The company has not disclosed the specific CVE identifier or the number of affected individuals.
Oracle E-Business Suite vulnerabilities have become a recurring target for threat actors seeking access to corporate systems. The platform's widespread use in enterprise HR and financial operations makes it a high-value target, particularly when organizations delay patching known flaws. Estée Lauder's breach underscores the risk profile of aging enterprise software in customer-facing corporations.
- 01Consumer goods firms using Oracle E-Business Suite face elevated scrutiny of patch cadence
- 02HR systems now priority targets, exposing employee and customer data simultaneously
- 03Regulatory notifications likely in multiple jurisdictions given Estée Lauder's global footprint
- 04Third-party enterprise software supply chain remains persistent weak point for large corporations
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.