Skip to content
October 7, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Data Leak
  • LocalBlox leaked 48 million personal data records
  • Data Leak

LocalBlox leaked 48 million personal data records

Do Son April 20, 2018 2 minutes read
Add Daily CyberSecurity as a preferred source on Google

The US data organization LocalBlox exposed an insecure online AWS library on the Internet that included some 48 million records from Facebook, LinkedIn, and Twitter.

“The UpGuard Cyber Risk Team can now confirm that a cloud storage repository containing information belonging to LocalBlox, a personal and business data search service, was left publicly accessible, exposing 48 million records of detailed personal information on tens of millions of individuals, gathered and scraped from multiple sources.” UpGuard posted a blog post describing it.

The AWS S3 bucket was discovered on February 18 by UpGuard’s director of cyber risk research, Chris Vickery, and it was exposed in the subdomain “lbdumps”.The bucket contains a single 151.3 GB compressed file titled “final_people_data_2017_5_26_48m.json”. After decompression, 1.2TB of data files will be obtained.

 

Analysis of the metadata in the file has led researchers to speculate that it belongs to LocalBlox.Records include data collected from social media such as name, address, and date of birth.It is easy to think of the nearest Cambridge Analytica case.

“In the wake of the Facebook/Cambridge Analytica debacle, the importance of massive sets of psychographic data is becoming more and more apparent. The exposed LocalBlox dataset combines standard personal information like name and address, with data about the person’s internet usage, such as their LinkedIn histories and Twitter feeds.“

More serious than the Facebook data breach scandal, Localblox collects data that is more aggressive, including highly sensitive personal information, and can even correspond to each individual’s personal identity—all without user consent. What happened next.This data is stored as a JSON file and can be read directly.The data includes name, home address, job information, career history, etc.

 

Localbox also frequently boasted about what they could collect before.The sample information on the company’s website claims that it also contains a person’s location, email address, IP address, telephone number, zip code, salary, employer, job title, and other precise information.Some data even includes whether a person has a credit card, marital status, and net assets.

After the researchers notified, LocalBlox had password protected the database on the same day, but no statement was issued on this occasion.

Source: securityaffairs

Related coverage

  • The Fatal Human Error: How One Manual Step Leaked Claude Code to the World
  • Former NSA contractor plead guilty due to stealing 50TB confidential data plans
  • US Threatens UK Over iCloud Backdoor Demand
  • Check Your Inbox: Booking.com Forced to Reset PINs After Major Data Leak
  • Seychelles Commercial Bank Hacked: Customer Data Compromised, Suspected Espionage Disguised as Cybercrime
  • Intel OEM Private Key Leak: A Blow to UEFI Secure Boot Security
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: LocalBlox

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-94504CVSS 7.2
    Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-93836CVSS 7.2
    The WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the \'qty\'...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-21589CVSS 9.3
    This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-61500CVSS 9.3
    Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs...
    Admin intel📅 Updated: Oct 7, 2026
  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-105324CVSS 9.2
    An HTTP header injection vulnerability in start-page-loader.cgi of ADM allows an unauthenticated remote attacker to read arbitrary files...
    📅 Updated: Oct 7, 2026
  • CVE-2026-79796CVSS 9.8
    Vulnerabilities have been identified in the affected interface of ClearPass Policy Manager that could potentially allow an unauthenticated...
    📅 Updated: Oct 7, 2026
  • CVE-2026-76464CVSS 9.6
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has...
    📅 Updated: Oct 7, 2026
  • CVE-2026-51862CVSS 9.1
    DB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remote attacker can use the validated exploitation path to...
    📅 Updated: Oct 7, 2026
  • CVE-2026-51869CVSS 9.8
    DB-GPT v0.8.0 sandbox API silently falls back to LocalRuntime and executes code on host.
    📅 Updated: Oct 7, 2026
  • CVE-2026-76501CVSS 9.8
    A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS...
    📅 Updated: Oct 7, 2026
  • CVE-2026-76500CVSS 9.8
    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller...
    📅 Updated: Oct 7, 2026
  • CVE-2026-102255CVSS 10.0
    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access...
    📅 Updated: Oct 7, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.