A serious expert discovered a flaw in PwnedList service that could have been exploited to access millions of account credentials managed by the service. Security expert Bob Hodges discovered a serious flaw in the service, he was trying to monitor domains when he discovered a security issue that allowed him to monitor any domain. The issue affects the two-step process implemented by the PwningList service to add new elements to the watchlist. An attacker could abuse the service to gather information to target a specific organization and gather its account credentials. The operators of the website temporary shut down the service in order to fix the problem.”]
Source: http://securityaffairs.co/wordpress/46913/hacking/pwnedlist-data-leak.html

