Monday, November 25, 2024
HomeCyber Security NewsTumblr Fixes Critical Security Bug That Exposes User Account Details

Tumblr Fixes Critical Security Bug That Exposes User Account Details

Published on

Tumblr Fixes a security bug with its desktop version that allows an attacker to steal the user’s personal information.

The bug appears to be in the “Recommended Blogs” section with the desktop version of the Tumblr. The future is available for users only after login and it shows the list of blogs the user follows.

Tumblr said that “it was possible, using debugging software in a certain way, to view certain account information associated with the blog.”

- Advertisement - SIEM as a Service

The bug was found by a security researcher who participated in the bug bounty program and the bug was fixed by Tumblr within 12hrs.

“Most importantly, there is no action required of you. We’ve resolved the issue, and have no evidence of this security bug being abused,” Tumblr said.

The bug allows an attacker to access certain user account information such as email address, hashed password, self-reported location, previously used email addresses, last login IP address, and the name of the blog associated with the account.

Tumblr said there is no evidence that this bug was abused, and there is nothing to suggest that unprotected account information was accessed.

Tumblr is a microblogging and social networking website, it allows users to post multimedia contents and a short-form blog.

Facebook admitted a security breach last month that impacts 30 million user accounts, hackers gained access by exploiting a bug with “View As” feature.

Google announced Google+ shut down following the security breach that exposed 500,000 Google+ accounts.

Related Read

Hackers Exploited Facebook Zero-Day Flaw & Stolen 50 Million Accounts Access Tokens

Hackers Selling Facebook Account Logins Details On Dark Web For $3

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Threat Actors Exploit Google Docs And Weebly Services For Malware Attacks

Phishing attackers used Google Docs to deliver malicious links, bypassing security measures and redirecting...

Python NodeStealer: Targeting Facebook Business Accounts to Harvest Login Credentials

The Python-based NodeStealer, a sophisticated info-stealer, has evolved to target new information and employ...

XSS Vulnerability in Bing.com Let Attackers Send Crafted Malicious Requests

A significant XSS vulnerability was recently uncovered in Microsoft’s Bing.com, potentially allowing attackers to...

Meta Removed 2 Million Account Linked to Malicious Activities

 Meta has announced the removal of over 2 million accounts connected to malicious activities,...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Threat Actors Exploit Google Docs And Weebly Services For Malware Attacks

Phishing attackers used Google Docs to deliver malicious links, bypassing security measures and redirecting...

Python NodeStealer: Targeting Facebook Business Accounts to Harvest Login Credentials

The Python-based NodeStealer, a sophisticated info-stealer, has evolved to target new information and employ...

XSS Vulnerability in Bing.com Let Attackers Send Crafted Malicious Requests

A significant XSS vulnerability was recently uncovered in Microsoft’s Bing.com, potentially allowing attackers to...