The critical vulnerability appears to affect Twitter in its core features and allow remote execution of commands!!!

In recent days, cases have been made public that are directly related to security on Twitter. Specifically, we recall that the profile of Facebook founder Mark Zuckerberg fell victim to a hacker attack while at the same time, complete databases with Twitter user passwords are circulating on the Darknet for the price of 10 Bitcoins. Security experts and media were quick to report that the attack did not “hit” Twitter but that some sophisticated Malware with the ability to intercept passwords stole user information such as usernames and access passwords. But is this really the case or is something more serious happening?

About 24 hours ago, a user of the most well-known security bug bounty platform Hackerone received a huge amount from Twitter as a reward for finding a bug!

Specifically, it appears that the user with the nickname filedescriptor received the amount of $15,120 (!). We estimate that Twitter did not want to announce more details about this specific vulnerability and as we can see, during the announcement of the payment, the details have been completely hidden, even the title of the vulnerability!

If one carefully reads the Twitter bounty program on the Hackerone platform, it is clear that this amount concerns a reward for vulnerabilities that allow the attacker to remotely execute commands (remote code execution) that affect Core Twitter. See the relevant table for details:

The user filedescriptor is from Hong Kong and is one of the most renowned and successful “bug bounty hunters” in the world. His proven track record in identifying serious vulnerabilities in giant companies (such as Twitter), ranks him by far among the best “ethical hackers” in the world!
You can also read filedescriptor's highly specialized posts on his website [here]

Until (if and when) there is an official announcement from Twitter, we cannot be ABSOLUTELY sure about the type of vulnerability that was identified and its exact solution. However, the accompanying evidence we have collected proves that a very serious vulnerability existed on Twitter until 24 hours ago and was probably fixed after filedescriptor pointed it out.
We recommend that our readers-Twitter users change their password IMMEDIATELY AND activate the two-factor authentication feature.
But what if this vulnerability had been identified earlier by malicious users? Are the latest cases of leaks on Twitter ultimately related to the vulnerability that was identified & fixed, as everything indicates 24 hours ago? Or is the scenario of malware spreading to users valid?
So, while we await more enlightening announcements, stay tuned for anything new.
PS: SecNews also has its own rewards program, with the start of our collaboration with Hackerone. Please read carefully the terms of our vulnerability reward program and submit your reports through the platform.
You can register and test the security of our website here: https://hackerone.com/secnews
