Last week, experts from Bitdefender published a detailed description of how hackers exploited a cross-site scripting vulnerability found on Yahoo!'s Developer Network Blog to steal user cookies and use them to gain access to their account. Yahoo! once again claims to have looked into the issue and fixed the vulnerability.

Yahoo!'s blog was vulnerable because it was using an old version of WordPress.
Yahoo! representatives told PCWorld today that the security hole has been addressed. The company is urging customers concerned about the security of their accounts to change their passwords and use two-factor authentication.
📧
Subscribe to the SecNews Newsletter
