More than 1,000 Twitter employees had the security access needed to aid hackers
Friday, July 24, 2020
According to Ilia Kolochenko, founder and CEO of web security company ImmuniWeb, the attack was "enhanced by exploitation of other weaknesses in Twitter’s internal security”.
“It is not excluded that the attackers were assisted by an insider or were exploiting a high-risk vulnerability detected in one of Twitter's web systems. Otherwise, we may reasonably infer that Twitter has virtually no internal security controls and best practices that we should normally expect from a tech company of its size,” he said.
Meanwhile, on a call to investors on Thursday, Twitter Chief Executive Jack Dorsey admitted to missteps: “We fell behind, both in our protections against social engineering of our employees and restrictions on our internal tools,” he said. Read Full Article
SC Media: Twitter hackers accessed direct messages for 36 accounts
The Telegraph: Ransom paid to hackers who stole data from at least six UK universities