Post Now
Image

A critical vulnerability was discovered in social networking website Tumblr which allows attackers to steal personal data and login credentials of users.

A critical vulnerability was discovered in social networking website Tumblr which allows attackers to steal personal data and login credentials of users. According to the report published by Tumblr, a security researcher reported the bug through bug bounty program and it was fixed within 12 hours of reporting. The bug was found on the Recommended Blogs” feature on the desktop version of Tumblr. The Recommended Blogs section shows a rotating list of blogs which other users may be interested and can be viewed only logged in users. “If a blog appeared in the module, it was possible, using debugging software in a certain way, to view certain account information associated with the blog.” The exposed data includes email addresses, protected (hashed and salted) password of the user account, self-reported location (which is no longer available ), previously used email addresses, last login IP address, and the name of the blog associated with the account. The company said they are still investigating the issue and still not was to determine the which specific accounts and no of users were affected by the bug. The company also said they did not find any evidence of any misuse of data or any information was accessed. “It’s our mission to provide a safe space for people to express themselves freely and form communities around things they love. We feel that this bug could have affected that experience. We want to be transparent with you about it. In our view, it’s simply the right thing to do. “ said in the post published by the company. Earlier Facebook and Google plus has announced data breaches. In Facebook, hackers were able to access personal data of 29 million accounts. In the case, Google+ a bug exposed user data of 500,000 users and was forced to shut down. For the latest cyber threats and the latest hacking news please follow us on FacebookLinkedin and Twitter.

You may be interested in reading:Critical Flaw in Branch.io Affects Around 685 Million Users