Thursday 30 May 2013

Drupal suffers mysterious hack, up to one million users affected

Content management system developer Drupal is urging its users to reset their passwords following a hack on customer data by an unknown third-party application.

Many creativesrus.com members are coders and developers who may well use Drupal software, and we would encourage those who do to read Drupal's offical FAQ regarding this incident, ensuring your online security.

It is estimated that approximately one million users may have their details compromised. Information exposed includes usernames, email addresses, and country information, as well as hashed passwords.

According to Michael Lee at ZDnet:

After exploiting a vulnerability in the third-party application, Drupal's attackers uploaded files to the association.drupal.org server, which Drupal detected during a routine security audit. The server was subsequently shut down and a resulting investigation found that users' account information had been accessed.

Drupal Director Holly Ross sought to pacify any fears of a serious security breach on her Twitter account.


No comments:

Post a Comment