Generated by TLDR This:
The head of Kiwi Farms, the Internet forum best known for organizing harassment campaigns against trans and non-binary people, said the site experienced a breach that allowed hackers to access his administrator account and possibly the accounts of all other users.
Assume any IP you've used on your Kiwi Farms account in the last month has been leaked.
The session hijacking was made possible after uploading malicious content to XenForo, a site Kiwi Farms uses to power its user forums.
While the command to download all users’ data didn’t appear to succeed, the attacker was able to load the file, most likely as an iframe, that caused certain users to send the attacker their Kiwi Farms authentication cookies.
“In fairness to Joshua (the Admin), he appears to know technically what he’s doing based on his comments in Telegram chat,” independent researcher Kevin Beaumont wrote on Twitter in a thread documenting the breach. Unfortunately for him all the companies he’s working with and the users... Don’t.”
Jump in the discussion.
No email address required.
Arse
technica posts a nothingburger with fewer words and details than found on the telegram
Jump in the discussion.
No email address required.
journ*lism
Jump in the discussion.
No email address required.
Jump in the discussion.
No email address required.
More options
Context
More options
Context
More options
Context