NEW: The notorious stalkerware TheTruthSpy has a security flaw that lets anyone reset any user's password, allowing them to access the private data of the people the users are spying on.
The security researcher who told us about the flaw also alerted the company, but did not get an answer.
When we told the TheTruthSpy owner, he said he won't fix the bug, which puts people who likely don't know they're being spied on at huge risk.
We verified the bug by giving the researcher usernames of test accounts, and he changed the passwords immediately.

A new security flaw in TheTruthSpy phone spyware is putting victims at risk | TechCrunch
Exclusive: Hackers can take over the accounts of TheTruthSpy spyware customers, putting their victims' private phone data at risk thanks to a new security flaw.

TechCrunch (techcrunch.com)