Blog | G5 Cyber Security

A flaw in US Postal Service website exposed data on 60 Million Users

US Postal Service has patched a critical bug that allowed anyone who has an account at usps.com to view and modify account details for other users. The problem resides in the USPS Informed Visibility API designed to to let businesses, advertisers and other bulk mail senders make better business decisions by providing them with access to near real-time tracking data about mail campaigns and packages. The issue was first reported by popular investigator Brian Krebs who was contacted by a researcher who discovered the issue more than a year ago.”]

Source: https://securityaffairs.co/wordpress/78298/hacking/us-postal-service-flaws.html

Exit mobile version