:

TP-LINK KASA CAMERAS LEAKED HOME GPS FOR 6 YEARS

INDUSTRY DESK1 MIN READ
SAT, JUL 18, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

TP-Link Kasa smart cameras transmitted home GPS coordinates via unencrypted, unauthenticated UDP packets for six years, exposing the physical locations of users to anyone on the network.

The vulnerability affected Kasa EC71 cameras and potentially other models in the lineup. Researchers discovered the cameras sent precise location data through UDP without authentication, allowing attackers to intercept and determine where devices were installed. The flaw persisted from the cameras' initial release through at least 2024, suggesting a significant gap in TP-Link's security review process. UDP packets can be captured by anyone monitoring network traffic, making the exposure particularly severe for home security devices designed to protect residences. TP-Link has not yet issued a public statement regarding the vulnerability. Affected users should update firmware immediately once patches become available. This incident highlights ongoing security concerns with IoT devices, where manufacturers frequently prioritize connectivity over baseline encryption and authentication measures. The research was shared publicly on GitHub, allowing users to assess their own exposure.

■ SOURCES

Hacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler, according to Previdian. CVE-2026-19490 allows threat actors to circumvent security controls on the widely-deployed application delivery platform.

JUST NOWIndustry Desk

A researcher known as Nightmare Eclipse has disclosed a CrowdStrike Falcon zero-day exploit called FalconFlank that enables privilege escalation on fully patched Windows systems. The vulnerability affects the widely-deployed endpoint protection software.

2H AGOSecurity Desk

The U.S. military has disabled ad tracking on service members' devices after foreign adversaries exploited location data to target troops. A senator's letter confirms the action was taken in response to security threats.

2H AGOIndustry Desk

Google has released an emergency update for Chrome to fix a high-severity zero-day vulnerability in the V8 engine currently being exploited in attacks. The update addresses this flaw plus 11 additional vulnerabilities.

4H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.