Most Viewed Content:

OpenAI Launched Assistants API, Allowing Developers to Customize AI Assistants with One Click

At today's OpenAI's first developer conference, OpenAI launched the...

Microsoft working on new features for Win11 / Win12: smart notifications, depth-of-field effects

According to the source Albacore (@thebookisclosed), Microsoft is preparing...

Google to bring PWA application backup & restore function for Chrome/android

According to thespAndroid reports, GitHub's Chromium repository recently added...

Twitter admits zero-day vulnerability led to the theft of 5.4 million users’ data and has now been fixed

Twitter has acknowledged that the recently revealed user data breach was made possible by hackers using a zero-day vulnerability, which has now been fixed. The vulnerability existed in a feature that tied email addresses and phone numbers to user accounts, leading hackers to access a list file containing 5.4 million user accounts.

Last month BleepingComputer learned that a hacker said they could exploit a vulnerability on the social media site to create a list of 5.4 million Twitter account profiles.

This vulnerability allows anyone to submit an email address or phone number, verify that it is associated with a Twitter account, and retrieve the associated account ID. threat actors then use this ID to grab public information about the account.

This allowed the attackers to create 5.4 million Twitter user profiles in December 2021, including verified phone numbers or email addresses, and to grab public information such as the number of followers, screen names, logins, locations, profile picture URLs, and other information.

BleepingComputer has since learned that two different threat actors purchased the data for less than the original asking price and that the data may be released for free in the future.

Today, Twitter has confirmed that the vulnerability used by the threat actors in December was the same one they reported and fixed in January 2022 as part of their HackerOne vulnerability bounty program.

In today’s security bulletin, Twitter disclosed, “In January 2022, we received a report of a vulnerability through our Vulnerability Bounty Program that allowed someone to identify the email or phone number associated with an account, or, if they knew someone’s email or phone number, they could identify their Twitter account if one exists.”

Latest

OPPO Find X7 confirmed to be launched in pure White color

The OPPO Find X7 standard version phone was released...

New electric Mini Cooper starts pre-sale: 3 models, 210,000-270,000 RMB

MINI released the new electric MINI COOPER model. Pre-sales...

Audi SQ6 e-tron debuts at the 2024 Beijing Auto Show

At the 2024 Beijing Auto Show, the Audi SQ6...

2024 Beijing Auto Show: Lynk & Co 07 EM-P starts pre-sale

At the 2024 Beijing Auto Show, Lynk & Co...

Newsletter

Don't miss

OPPO Find X7 confirmed to be launched in pure White color

The OPPO Find X7 standard version phone was released...

New electric Mini Cooper starts pre-sale: 3 models, 210,000-270,000 RMB

MINI released the new electric MINI COOPER model. Pre-sales...

Audi SQ6 e-tron debuts at the 2024 Beijing Auto Show

At the 2024 Beijing Auto Show, the Audi SQ6...

2024 Beijing Auto Show: Lynk & Co 07 EM-P starts pre-sale

At the 2024 Beijing Auto Show, Lynk & Co...

2024 Beijing Auto Show: Genesis G80 Magma EV Unveiled

At the 2024 Beijing Auto Show, the Genesis G80...
Threza Gabriel
Threza Gabrielhttps://www.techgoing.com
Threza Gabriel is a news writer at TechGoing. TechGoing is a global tech media to brings you the latest technology stories, including smartphones, electric vehicles, smart home devices, gaming, wearable gadgets, and all tech trending.

Tesla Cybertruck Recalled Over Stuck Accelerator Pedal Risk, Fixed with Rivets

Tesla has recently suspended deliveries and recalled all Cybertruck electric pickup trucks. A popular online video showed that the rubber pad of the Cybertruck...

Google Android 15: Restricts sideloaded apps from obtaining sensitive permissions

Foreign technology media Android Authority recently excavated the latest Android 15 Beta 1.1 update and discovered the "Enhanced Confirmation Mode" in the code, which...

Mercedes-Benz to Unveil New E-Class Standard-Axis Sports Version at Beijing Auto Show

Recently, we learned from Mercedes-Benz officials that the new Mercedes-Benz E-Class standard wheelbase sports version (W214) will be officially unveiled at the Beijing Auto...