Rampant worm exploits Tumblr hole

By

Thousands of users affected.

A hacking group has unleashed a worm which defaced thousands of Tumblr websites.

Rampant worm exploits Tumblr hole

The infection spread to some 8000 pages via a vulnerability in the blogging platform and possibly though a suspected Java hole.

The group known as GNAA behind the attack said they warned Tumblr of the vulnerability but it did not respond. No further details on the hole were revealed and the security hole has been since fixed.

USA Today and Reuters were among the Tumblr pages struck by the worm. 

The Daily Dot which was a victim of the attacks said the worm was buried in a link within the defacement which when clicked allowed the post to propagate to the victim's Tumblr blog.

The worm did not appear to inflict any other harm than to spread the inflammatory spam message. Users' accounts were not compromised.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

CBA using facial recognition logins to verify disputed payments

CBA using facial recognition logins to verify disputed payments

Researchers demo AI-crippling GPUHammer attack

Researchers demo AI-crippling GPUHammer attack

Qantas obtains court order to prevent third-party access to stolen data

Qantas obtains court order to prevent third-party access to stolen data

Google Gemini for Workspace vulnerable to prompt injection attacks

Google Gemini for Workspace vulnerable to prompt injection attacks

Log In

  |  Forgot your password?