Twitter confirms vulnerability resulted in over 5 million accounts exposed
Twitter released a statement on Friday confirming that a vulnerability they had patched earlier this year was, in fact, used in a malicious attack to collect user data.
The company was forced to come clean after media reports about hacked account details surfaced on the web. According to Twitter, the company became aware of the problem in January 2022 via the company's bug bounty program. The bug had been in the code since June 2022 and was quickly fixed.
Now, the actual vulnerability and the exploit of it has to do with a form that provides the Twitter ID associated with the submitted phone number or email address. This shouldn't be publicly available, and according to a HackerOne report to Twitter, this happened even when the user had explicitly prohibited this action in the Twitter privacy settings.
This was abused to create lists consisting of Twitter IDs, phone numbers, and email addresses.
Last month Restore Privacy reported that over 5 million Twitter accounts were exposed by a hacker that was selling the database with Twitter IDs, phone numbers, and email addresses. For $30,000, the hacker by the name of "devil" claimed, you could receive information about "Celebrities, Companies, randoms, OGs, etc."

Shopping giant Amazon has somewhat unexpectedly moved in to acquire leading robot vacuum manufacturer iRobot. The acquisition cost is $1.7 billion, companies'
The leading semiconductor corporation Qualcomm has announced new Snapdragon chips for wearables. The upcoming Snapdragon W5 Gen 1 and Snapdragon W5+ Gen 1 system-on-chips provide vastly improved power management among other changes.






