Rampant worm exploits Tumblr hole

By

Thousands of users affected.

A hacking group has unleashed a worm which defaced thousands of Tumblr websites.

Rampant worm exploits Tumblr hole

The infection spread to some 8000 pages via a vulnerability in the blogging platform and possibly though a suspected Java hole.

The group known as GNAA behind the attack said they warned Tumblr of the vulnerability but it did not respond. No further details on the hole were revealed and the security hole has been since fixed.

USA Today and Reuters were among the Tumblr pages struck by the worm. 

The Daily Dot which was a victim of the attacks said the worm was buried in a link within the defacement which when clicked allowed the post to propagate to the victim's Tumblr blog.

The worm did not appear to inflict any other harm than to spread the inflammatory spam message. Users' accounts were not compromised.

This article originally appeared at scmagazineus.com

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

NSW Police to embark on $126m IT overhaul

NSW Police to embark on $126m IT overhaul

CBA looks to GenAI to assist 1200 'security champions'

CBA looks to GenAI to assist 1200 'security champions'

Australia's super funds told to assess authentication controls

Australia's super funds told to assess authentication controls

WestJet probes cyber security incident

WestJet probes cyber security incident

Log In

  |  Forgot your password?