Yahoo Mail is considered one of the worst email services on the internet in terms of security. In 2014, the company exposed 500 million accounts after a hack, but decided to keep it a secret, exposing its users to very serious risks.
What has changed today? Probably not too much:
Security researcher Jouko Pynnonen has discovered a cross-site scripting (XSS) security flaw in Yahoo Mail that essentially allows an attacker to access any account and read emails freely.
Yahoo reportedly fixed this flaw last week by rewarding the researcher with $10,000, according to the company's bug bounty program.
Pynnonen explained that it was possible for an attacker to infiltrate the company's accounts simply by bypassing the HTML filtering that Yahoo uses for links hiding malicious JavaScript code.
Worst of all, users didn't even have to click on links or open attachments. They just had to open the email the hacker sent them.
"The flaw allows an attacker to read a victim's email or create a virus to infect Yahoo Mail accounts, among other things. The attack requires the victim to view an email message sent by the attacker. No further interaction (such as clicking a link or opening an attachment) is required," the researcher says.
Yahoo was notified of the hack on November 12th and fixed it on November 29th. So now you're supposedly safe.
https://klikki.fi/adv/yahoo2.html
