Monday, January 27, 2025
HomeCyber AttackHackers Exploited Facebook Zero-Day Flaw & Stolen 50 Million Accounts Access Tokens

Hackers Exploited Facebook Zero-Day Flaw & Stolen 50 Million Accounts Access Tokens

Published on

SIEM as a Service

Follow Us on Google News

Facebook security breach, hackers steal more than 50 million accounts access tokens by exploiting a bug in View As a feature.

The access token contains information such as security credentials for a login session, user identity, and the permission. By having the access tokens hackers can take over user accounts without account passwords and without completing two-factor authentication.

Facebook Security Breach Noticed

Facebook noticed the Bug on September 25 and they said the bug was fixed now and reported to law enforcement agencies. Facebook not revealed any technical details of the vulnerability.

The social media giant said “we have reset the access tokens of the almost 50 million accounts and as a precautionary step of resetting access tokens for another 40 million accounts that have been subject to a “View As” look-up in the last year,” reads Facebook security breach update.

So as the token reset the affected users need to lo back in with the Facebook or any other apps that use Facebook login.

Facebook made changes with code for View as a feature while introducing video uploading feature in July 2017 and the attackers found the vulnerability in the code and use it to get the access tokens.

Temporarily facebook turned off View as a feature, that lets you see how your profile looks for others.

The social media giant said we just started the investigation, we have yet to determine whether these accounts were misused or any information accessed. We also don’t know who’s behind these attacks or where they’re based.

Facebook under heavy criticism after Cambridge Analytica scandal which impacts more than 87 Million users and thereafter many Quiz app NameTests spotted exposing more than 120 million users personal data publically in third-party sites.

In a recent analysis report, more than 25,000 it was found that Malicious Apps Use Facebook APIs to Obtain a Range of Information.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

White House Considers Oracle-Led Takeover of TikTok with U.S. Investors

In a significant development, the Trump administration is reportedly formulating a plan to prevent...

Critical Vulnerability in IBM Security Directory Enables Session Cookie Theft

IBM has announced the resolution of several security vulnerabilities affecting its IBM Security Directory...

Critical Apache Solr Vulnerability Grants Write Access to Attackers on Windows

A new security vulnerability has been uncovered in Apache Solr, affecting versions 6.6 through...

GitHub Vulnerability Exposes User Credentials via Malicious Repositories

A cybersecurity researcher recently disclosed several critical vulnerabilities affecting Git-related projects, revealing how improper...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

White House Considers Oracle-Led Takeover of TikTok with U.S. Investors

In a significant development, the Trump administration is reportedly formulating a plan to prevent...

Critical Vulnerability in IBM Security Directory Enables Session Cookie Theft

IBM has announced the resolution of several security vulnerabilities affecting its IBM Security Directory...

Critical Apache Solr Vulnerability Grants Write Access to Attackers on Windows

A new security vulnerability has been uncovered in Apache Solr, affecting versions 6.6 through...