Stalkerware researcher maia arson crimew strikes again. Big time. We know maia as a researcher that loves to go after stalkerware peddlers, which Malwarebytes—as one of the founding members of the Coalition Against Stalkerware—loves to see.
The investigation into Tracki, besides uncovering a tangled web of companies, dubious websites, and false identities, also led to a data breach that maia says could possibly affect almost 12 million users. Researching the technology behind the tracker and the web portal for customers that want to see all their trackers on a map, maia found various hardcoded usernames and passwords used to load data from a number of administration and support tools.
Read more…
Source: Malwarebytes Labs
Related:
- Stolen UK identities selling for as little as £10 on the dark web
December 26, 2018
Stolen personal data of UK citizens is selling for as little as £10 on the dark web, offering hackers all the information needed to carry out online fraud and identity theft, The Independent has discovered. So-called fullz – hacker slang meaning a “full ID” package – of UK citizens are being listed on several popular online black markets. A full ID ...
- Facebook Flaw Exposes Private Photos for 6.8M Users
December 14, 2018
The bug allowed 1,500 apps built by 876 developers to view users’ unposted “draft” photos. Facebook on Friday disclosed a bug in its platform that it said enabled third-party apps to access unpublished photos of 6.8 million users. Facebook stores copies of photo drafts, so if someone uploads the photo but doesn’t finish posting it, the photo ...
- Personal Information of 52.5 Million Exposed by New Google+ People API Bug
December 10, 2018
“With the discovery of this new bug, we have decided to expedite the shut-down of all Google+ APIs; this will occur within the next 90 days,” said David Thacker, G Suite Product Management VP. “In addition, we have also decided to accelerate the sunsetting of consumer Google+ from August 2019 to April 2019.” Google discovered the bug in ...
- Senators Push for Data Breach and Privacy Legislation Following Marriot Breach
December 3, 2018
U.S. Democrat Senators Mark Warne, Ed Markey, and Richard Blumenthal published statements asking for the passage of data security and consumer privacy legislation by the Congress following the Marriot International hotel chain breach. The Marriott hotel chain disclosed a huge data breach on November 30 which affected 500 million customers who had their data stored in ...
- 500 Million Marriott Guest Records Stolen in Starwood Data Breach
November 30, 2018
The world’s biggest hotel chain Marriott International today disclosed that unknown hackers compromised guest reservation database its subsidiary Starwood hotels and walked away with personal details of about 500 million guests. Starwood Hotels and Resorts Worldwide was acquired by Marriott International for $13 billion in 2016. The brand includes St. Regis, Sheraton Hotels & Resorts, W ...
- Uber fined $1.1 million by UK and Dutch regulators over 2016 data breach
November 29, 2018
British and Dutch data protection regulators Tuesday hit the ride-sharing company Uber with a total fine of $1,170,892 (~ 1.1 million) for failing to protect its customers’ personal information during a 2016 cyber attack involving millions of users. Late last year, Uber unveiled that the company had suffered a massive data breach in October 2016, exposing names, email ...
