May 182018
 
 May 18, 2018  Posted by  Breaches, Business, Featured News, U.S.

Brian Krebs reports:

LocationSmart, a U.S. based company that acts as an aggregator of real-time data about the precise location of mobile phone devices, has been leaking this information to anyone via a buggy component of its Web site — without the need for any password or other form of authentication or authorization — KrebsOnSecurity has learned. The company took the vulnerable service offline early this afternoon after being contacted by KrebsOnSecurity, which verified that it could be used to reveal the location of any AT&T, Sprint, T-Mobile or Verizon phone in the United States to an accuracy of within a few hundred yards.

Read more on  KrebsOnSecurity.com.

Sorry, the comment form is closed at this time.