- Facebook copies Instagram with experimental ‘Popular Photos’ feature 1 Year Ago
- This iPhone app says it will alert you if you’ve been hacked Today 2:43 PM
- ‘Marvel’s Hero Project’ is the wholesome content 2019 needs Today 2:40 PM
- Get more out of VSCO with VSCO search Today 2:09 PM
- Twitter carves out ‘cause-based’ advocacy exemption in political ads ban Today 2:06 PM
- Disney+ accounts are being hacked—here’s how to protect yourself Today 1:52 PM
- Instagram is hiding likes globally and searching for a ‘well-being’ product researcher Today 1:42 PM
- ‘The Mandalorian’ opens up its mythology even further in ‘Chapter 2’ Today 12:54 PM
- Want to buy a drone on a budget? We’ve got you covered Today 12:51 PM
- ‘Simpsons’ writer accuses Republicans of stealing Sideshow Bob’s defense Today 12:49 PM
- Keanu Reeves’ appearance in ‘SpongeBob Movie’ trailer quickly becomes a meme Today 12:35 PM
- Charli XCX makes the band in Netflix’s ‘Nasty Cherry’ Today 12:33 PM
- Taylor Swift’s distress call reignites fight with Scooter Braun and former label Today 12:16 PM
- How to disable autoplay for previews and trailers on Disney+ Today 12:10 PM
- College basketball stream: How to watch North Carolina vs. Gardner-Webb Today 12:00 PM
A major Tumblr security bug potentially exposed its users’ private data, but the blogging service says it has patched the problem.
The vulnerability, discovered by a security researcher participating in the company’s bug bounty program, involved Tumblr’s “Recommended Blogs” feature utilized by the service’s desktop app.
A blog post from the company explaining the issues states: “If a blog appeared in the module, it was possible, using debugging software in a certain way, to view certain account information associated with the blog.”
“This included email address, protected (hashed and salted) password of the Tumblr account, self-reported location (a no longer available feature), previously used email addresses, last login IP address, and the name of the blog associated with the account,” the company revealed.
Tumblr emphasized that an internal investigation yielded “no evidence of this security bug being abused” and said the issue was fixed within 12 hours of being reported.
“We’re not able to determine which specific accounts could have been affected by this bug, but our analysis has shown that the bug was rarely present,” Tumblr said.
The blog adds that users are not required to take any action as a result of the incident.
“It’s our mission to provide a safe space for people to express themselves freely and form communities around things they love. We feel that this bug could have affected that experience,” Tumblr concluded. “We want to be transparent with you about it. In our view, it’s simply the right thing to do.”
Bug bounty programs are used by numerous technology companies in order to reward security researchers for discovering issues that could be exploited by malicious actors.
While the most recent bug does not appear to have resulted in the compromise of private data, a hacker was able to steal account details from 65 million Tumblr users in 2016.
Mikael Thalen is a tech and security reporter based in Seattle, covering social media, data breaches, hackers, and more.