TP-LINK KASA CAMERAS LEAKED HOME GPS FOR 6 YEARS
■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
TP-Link Kasa smart cameras transmitted home GPS coordinates via unencrypted, unauthenticated UDP packets for six years, exposing the physical locations of users to anyone on the network.
■ MORE FROM THE SECURITY DESK
Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler, according to Previdian. CVE-2026-19490 allows threat actors to circumvent security controls on the widely-deployed application delivery platform.
A researcher known as Nightmare Eclipse has disclosed a CrowdStrike Falcon zero-day exploit called FalconFlank that enables privilege escalation on fully patched Windows systems. The vulnerability affects the widely-deployed endpoint protection software.
The U.S. military has disabled ad tracking on service members' devices after foreign adversaries exploited location data to target troops. A senator's letter confirms the action was taken in response to security threats.
Google has released an emergency update for Chrome to fix a high-severity zero-day vulnerability in the V8 engine currently being exploited in attacks. The update addresses this flaw plus 11 additional vulnerabilities.