Another T-Mobile bug gave anyone access to your sensitive info

Another T-Mobile bug gave anyone access to your sensitive info

The subdomain apparently had a hidden API that would surface personal details, so customer service reps couls look up subscribers’ details. Problem was, it wasn’t protected by a password. Bad actors can then use those details to reset people’s email and bank passwords, among other things, by convincing customer service reps that they’re the owner …