- Which 2020 Democratic candidates post the most cringe? 1 Year Ago
- The new ‘Hunger Games’ book paints President Snow as a hero—and people are not happy Tuesday 9:03 PM
- Influencer called out for ‘troubling image’ with Kenyan child Tuesday 8:18 PM
- Professor arrested for spending $185K of grant money on iTunes and strippers Tuesday 7:28 PM
- Man cuts his books in half to make them ‘portable,’ spurs online debate Tuesday 6:09 PM
- Fans defend Lana Del Rey after she was mocked for flying commercial Tuesday 5:10 PM
- Lady Gaga fans find alleged new song name in her website’s code Tuesday 4:42 PM
- Barstool Sports deletes anti-union tweets, blog post in settlement Tuesday 3:47 PM
- The ‘can have … as a treat’ meme has come full circle Tuesday 3:09 PM
- Joe Rogan says he’s voting for Bernie Sanders Tuesday 2:54 PM
- Woman spots mole in man’s TikTok video, saves him from cancer Tuesday 2:17 PM
- ‘You’ star confirms his character is queer and ‘never will be’ straight Tuesday 1:08 PM
- This Twitch streamer pooped his pants during a broadcast Tuesday 12:17 PM
- Apple’s iCloud encryption plan halted amid FBI pressure, report Tuesday 10:57 AM
- Glenn Greenwald charged with cybercrimes in Brazil Tuesday 10:48 AM
A major Tumblr security bug potentially exposed its users’ private data, but the blogging service says it has patched the problem.
The vulnerability, discovered by a security researcher participating in the company’s bug bounty program, involved Tumblr’s “Recommended Blogs” feature utilized by the service’s desktop app.
A blog post from the company explaining the issues states: “If a blog appeared in the module, it was possible, using debugging software in a certain way, to view certain account information associated with the blog.”
“This included email address, protected (hashed and salted) password of the Tumblr account, self-reported location (a no longer available feature), previously used email addresses, last login IP address, and the name of the blog associated with the account,” the company revealed.
Tumblr emphasized that an internal investigation yielded “no evidence of this security bug being abused” and said the issue was fixed within 12 hours of being reported.
“We’re not able to determine which specific accounts could have been affected by this bug, but our analysis has shown that the bug was rarely present,” Tumblr said.
The blog adds that users are not required to take any action as a result of the incident.
“It’s our mission to provide a safe space for people to express themselves freely and form communities around things they love. We feel that this bug could have affected that experience,” Tumblr concluded. “We want to be transparent with you about it. In our view, it’s simply the right thing to do.”
Bug bounty programs are used by numerous technology companies in order to reward security researchers for discovering issues that could be exploited by malicious actors.
While the most recent bug does not appear to have resulted in the compromise of private data, a hacker was able to steal account details from 65 million Tumblr users in 2016.
Mikael Thalen is a tech and security reporter based in Seattle, covering social media, data breaches, hackers, and more.