Tumblr Fixes a security bug with its desktop version that allows an attacker to steal the user’s personal information.
The bug appears to be in the “Recommended Blogs” section with the desktop version of the Tumblr. The future is available for users only after login and it shows the list of blogs the user follows.
Tumblr said that “it was possible, using debugging software in a certain way, to view certain account information associated with the blog.”
The bug was found by a security researcher who participated in the bug bounty program and the bug was fixed by Tumblr within 12hrs.
“Most importantly, there is no action required of you. We’ve resolved the issue, and have no evidence of this security bug being abused,” Tumblr said.
The bug allows an attacker to access certain user account information such as email address, hashed password, self-reported location, previously used email addresses, last login IP address, and the name of the blog associated with the account.
Tumblr said there is no evidence that this bug was abused, and there is nothing to suggest that unprotected account information was accessed.
Tumblr is a microblogging and social networking website, it allows users to post multimedia contents and a short-form blog.
Facebook admitted a security breach last month that impacts 30 million user accounts, hackers gained access by exploiting a bug with “View As” feature.
Google announced Google+ shut down following the security breach that exposed 500,000 Google+ accounts.
Hackers Exploited Facebook Zero-Day Flaw & Stolen 50 Million Accounts Access Tokens
Hackers Selling Facebook Account Logins Details On Dark Web For $3
A critical security flaw has been uncovered in certain TP-Link routers, potentially allowing malicious actors…
SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce shoppers…
The research revealed how threat actors exploit SEO poisoning to redirect unsuspecting users to malicious…
Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in 2022…
CVE-2024-52301 is a critical vulnerability identified in Laravel, a widely used PHP framework for building…
A critical vulnerability has been discovered in the popular "Really Simple Security" WordPress plugin, formerly…