Thursday, April 18, 2024

Disqus confirms it’s been hacked and more than 17.5 Million Users Details Exposed

Disqus the most famous commenting system late today confirmed the data breach that took place in the summer of 2012, which exposed more than 17.5 million user accounts online.

Leaked details include email addresses, Disqus usernames, sign-up dates, and last login dates in plain text for 17.5mm users, but passwords are hashed with SHA-1 and salted, which protects the compromised account.

Also Read POS Malware Breach at Sonic Affected Millions of Credit & Debit Cards

This breach was identified by the Aussie security researcher Troy Hunt, and according to Hunt’s tweet, Disqus took 23 hours and 42 minutes from initial private disclosure to public notification.

User Impact

Email address is in plain text, so affected users may receive Spam emails. They believe the data was not widely exposed and they also confirmed the exposed data is from July 2012.

Right now there isn’t any evidence of unauthorized logins occurring in relation to this. No plain text passwords were exposed, but it is possible for this data to be decrypted (even if unlikely). As a security precaution, we have reset the passwords for all affected users. We recommend that all users change passwords on other services if they are shared.Disqus says.

So if you started using Disqus after July 2012, then your account is not impacted by the breach.

Safety Measures were taken by Disqus

They started notifying users about the breach and forcing the reset of passwords for all affected users.Also, they tighten the database security.

They also said that toward the end of 2012 we changed our password hashing algorithm from SHA1 to bcrypt.

Also Read Deloitte Hacked by Cyber Criminals and Revealed Client & Employee’s Secret Emails


Latest articles

Xiid SealedTunnel: Unfazed by Yet Another Critical Firewall Vulnerability (CVE-2024-3400)

In the wake of the recent disclosure of a critical vulnerability (CVE-2024-3400) affecting a...

Cerber Linux Ransomware Exploits Atlassian Servers to Take Full Control

Security researchers at Cado Security Labs have uncovered a new variant of the Cerber...

FGVulDet – New Vulnerability Detector to Analyze Source Code

Detecting source code vulnerabilities aims to protect software systems from attacks by identifying inherent...

North Korean Hackers Abuse DMARC To Legitimize Their Emails

DMARC is targeted by hackers as this serves to act as a preventative measure...

L00KUPRU Ransomware Attackers discovered in the wild

A new variant of the Xorist ransomware, dubbed L00KUPRU, has been discovered in the...

Oracle Releases Biggest Security Update in 2024 – 372 Vulnerabilities Are Fixed – Update Now!

Oracle has released its April 2024 Critical Patch Update (CPU), addressing 372 security vulnerabilities...

Outlook Login Panel Themed Phishing Attack Evaded All Antivirus Detections

Cybersecurity researchers have uncovered a new phishing attack that has bypassed all antivirus detections.The...
Guru baran
Guru baran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.


Mastering WAAP/WAF ROI Analysis

As the importance of compliance and safeguarding critical websites and APIs grows, Web Application and API Protection (WAAP) solutions play an integral role.
Key takeaways include:

  • Pricing models
  • Cost Estimation
  • ROI Calculation

Related Articles