:

TP-LINK KASA CAMERAS LEAKED HOME GPS FOR 6 YEARS

INDUSTRY DESK1 MIN READ
SAT, JUL 18, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

TP-Link Kasa smart cameras transmitted home GPS coordinates via unencrypted, unauthenticated UDP packets for six years, exposing the physical locations of users to anyone on the network.

The vulnerability affected Kasa EC71 cameras and potentially other models in the lineup. Researchers discovered the cameras sent precise location data through UDP without authentication, allowing attackers to intercept and determine where devices were installed. The flaw persisted from the cameras' initial release through at least 2024, suggesting a significant gap in TP-Link's security review process. UDP packets can be captured by anyone monitoring network traffic, making the exposure particularly severe for home security devices designed to protect residences. TP-Link has not yet issued a public statement regarding the vulnerability. Affected users should update firmware immediately once patches become available. This incident highlights ongoing security concerns with IoT devices, where manufacturers frequently prioritize connectivity over baseline encryption and authentication measures. The research was shared publicly on GitHub, allowing users to assess their own exposure.

■ SOURCES

Hacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Anthropic has signed out some Claude users and removed saved payment methods after infostealer malware on their computers hijacked active sessions to drain API usage credits. The company is issuing refunds for unauthorized charges.

4H AGOAI Desk

Former NYC Traffic Commissioner Sam Schwartz warns that autonomous vehicle expansion creates significant cybersecurity risks, including the potential for bad actors to seize control of connected cars and weaponize them.

4H AGOSecurity Desk

More than a decade of Steam files, including beta builds and finished games from Valve and third-party developers, have been exposed in a major data leak totaling over 12 terabytes.

9H AGOIndustry Desk

A new vulnerability called Omarchy allows any user-level process to gain root privileges through privilege escalation. The flaw has sparked significant discussion in security circles.

11H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.