New Delhi: Micro-blogging site Twitter has said that the exploit that was used to obtain information from 5.4 million users on the platform has now been confirmed and fixed. However, while Twitter has confirmed the attack, it still leaves the data of 5.4 million Twitter users exposed and in the hands of a malicious attacker.
The zero-day attack took place in December 2021 and was reported last month.
The attacker said last month that he has data of about 5,485,636 accounts with information like location, URL, profile picture, and other data. The attacker allegedly used a vulnerability that allowed anyone to query a phone number or email to check an active Twitter account and obtain their information, News18 reported.
According to the Bleeping Computer, which first reported on the attack, the data was last being sold for $30,000, but the attacker had also said that the data could end up being released for free, putting millions of users at risk publicly. Twitter said it learned about the bug in January this year through its bug bounty programme. While the issue was fixed earlier this year, Twitter said that it didn’t account for the likelihood of the attacker already being in possession of the data, the report added.
According to an Android Police report, Twitter has said that it is notifying each user, but the company has admitted that it cannot confirm every account that was exposed due to this issue. While passwords were not a part of the compromised data, Twitter is advising users to turn on two-factor authentication for their accounts. Given that the phone number is the key threat vector, users are advised to go for either an authentication app or a hardware key, both of which can be set up with Twitter’s mobile app, the report said.
Bhubaneswar: The Election Commission of India (ECI) on Tuesday announced byelections to six Rajya Sabha,…
Bhadrak: Unidentified miscreants looted gold and silver jewellery and other valuables from four temples in…
Islamabad: The Shehbaz Sharif government on Tuesday deployed the Army in Islamabad along with 'shoot…
Puri: All fishing activities have been banned in the sea in Odisha’s Puri district for…
Bhubaneswar: The Depression over southwest Bay of Bengal is likely to move nearly north-northwestwards and…
Bhubaneswar: The winter session of Odisha Assembly began on a stormy note as the House…
New Delhi: President Droupadi Murmu released commemorative coin of Rs 75 denomination and stamp dedicated…
Bhubaneswar: Income Tax Department officials conducted simultaneous raids on multiple locations linked prominent mining company…