• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Zero-Day Bug Responsible for Massive Twitter Breach

You are here: Home / General Cyber Security News / Zero-Day Bug Responsible for Massive Twitter Breach
August 8, 2022

A zero-day vulnerability in Twitter’s code base was liable for a key info breach that is considered to have afflicted 5.4 million people, the social media organization has disclosed.

The threat actor was hoping to market the profile info for $30,000 on a cybercrime website. Some information and facts was scraped from general public Twitter profiles, together with area and picture URL. Even so, they ended up crucially ready to url account email messages and phone numbers with account IDs by leveraging the vulnerability.

“In January 2022, we acquired a report via our bug bounty software of a vulnerability in Twitter’s techniques. As a end result of the vulnerability, if somebody submitted an email deal with or phone selection to Twitter’s devices, Twitter’s techniques would notify the person what Twitter account the submitted email addresses or phone number was related with, if any,” Twitter stated.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


“This bug resulted from an update to our code in June 2021. When we learned about this, we quickly investigated and fastened it. At that time, we experienced no evidence to counsel a person had taken advantage of the vulnerability.”

Nevertheless, the firm understood past thirty day period that a malicious actor experienced in truth been ready to just take edge of the bug just before it managed to patch it.

“We will be instantly notifying the account house owners we can confirm were being influenced by this issue,” it explained.

“We are publishing this update mainly because we aren’t equipped to confirm just about every account that was most likely impacted, and are specially conscious of folks with pseudonymous accounts who can be focused by condition or other actors.”

The firm is recommending these who use Twitter pseudonymously not to incorporate a publicly known phone amount or email tackle to their account.

It also prompt consumers switch on two-factor authentication for extra login security, making use of both a devoted application or components security keys. Having said that, no passwords had been stolen in the attack.


Some elements of this article are sourced from:
www.infosecurity-magazine.com

Previous Post: «Cyber Security News NHS Cyber-Attack Delays Ambulances
Next Post: Cyber attack on software supplier causes “major outage” across the NHS cyber attack on software supplier causes "major outage" across the»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New FjordPhantom Android Malware Targets Banking Apps in Southeast Asia
  • Qakbot Takedown Aftermath: Mitigations and Protecting Against Future Threats
  • Chinese Hackers Using SugarGh0st RAT to Target South Korea and Uzbekistan
  • Discover How Gcore Thwarted Powerful 1.1Tbps and 1.6Tbps DDoS Attacks
  • WhatsApp’s New Secret Code Feature Lets Users Protect Private Chats with Password
  • U.S. Treasury Sanctions North Korean Kimsuky Hackers and 8 Foreign Agents
  • Zyxel Releases Patches to Fix 15 Flaws in NAS, Firewall, and AP Devices
  • Zero-Day Alert: Apple Rolls Out iOS, macOS, and Safari Patches for 2 Actively Exploited Flaws
  • Google Unveils RETVec – Gmail’s New Defense Against Spam and Malicious Emails
  • North Korea’s Lazarus Group Rakes in $3 Billion from Cryptocurrency Hacks

Copyright © TheCyberSecurity.News, All Rights Reserved.