BitDefender offers insights into recently discovered Facebook vulnerability
1 May 2011
IT in Manufacturing
Security provider advises users on how to stay protected against future after Facebook vulnerabilities.
Symantec recently discovered a security vulnerability that affected the way third-party programs, such as games and other applications, accessed user data and information. According to BitDefender, the entire issue is related to OAUTH, the secure authorisation protocol, and the use of some deprecated parameters by different applications which are still not updating from OAUTH to its latest version, OAUTH2.0.
From this vulnerability, third parties, such as advertisers can get hold of access tokens, which open Facebook users’ account information (such as basic information, profiles, pictures) and will sometimes give them the ability to perform different actions in the user’s name.
“At the current time, it is unclear whether there actually was a data breach or not. Symantec discovered a security issue and notified Facebook accordingly,” commented Catalin Cosoi, head of the BitDefender Online Threats Lab. “This could mean that the issue was proactively discovered and Facebook fixed it before anyone lost any data. On the other hand, it could mean that it is a known vulnerability in the underground or unethical world and users’ private data has been leaking for some time now.”
Facebook has solved this issue as soon as possible, but this episode teaches all users two main lessons:
(1) applications should have switched to the new authorisation mechanism as soon as possible, and
(2) If any data was leaked, there is not much to be done now, since it is lost for good.
Although it should not be the case here, information extracted from social media can be easily converted into directed attacks, like phishing, highly social engineered spam messages and possibly even identity theft. Users should pay extra attention in the following months when it comes to all messages received and be very careful when asked to perform different actions, even if the messages/requests come from a trusted source.
“This information can be illicitly used by marketers and advertisers in order to better profile their users and to serve ads based on interests and views. As always, a good way for Facebook users to invalidate their current access tokens is for them to change their passwords,” advised Cosoi.
Further reading:
ESG as a growth lever
RS South Africa
IT in Manufacturing
Leading organisations are treating ESG not as a compliance obligation but as a practical tool for operational efficiency, supply chain resilience and business performance, with data and collaboration central to unlocking its value.
Read more...
Preparing Africa’s data centres for the demands of autonomous AI
Schneider Electric South Africa
IT in Manufacturing
Africa’s data centre infrastructure must evolve significantly to support agentic AI workloads, with GPU-intensive computing, advanced cooling and reliable power demanding a fundamentally different approach to facility design and investment.
Read more...
Virtualising the control room to reshape building management systems
Schneider Electric South Africa
IT in Manufacturing
Schneider Electric explains how virtualising building management systems frees facilities teams from ageing hardware, delivers stronger cybersecurity and enables portfolio-wide control from a single interface.
Read more...
AI infrastructure solutions for data campus
Schneider Electric South Africa
IT in Manufacturing
Schneider Electric and Motivair deliver more than $290 million in power and cooling infrastructure for TeraWulf’s AI-ready Lake Mariner data campus.
Read more...
Africa’s data centre evolution: AI, edge computing and new energy demands
IT in Manufacturing
With less than half a gigawatt of active white space capacity serving over a billion people, Africa’s data centre sector faces a stark gap that AI’s surging power and cooling demands are set to widen. Vertiv and Open Africa Data Centres unpack how modularity, edge computing and smarter energy strategies could change the equation.
Read more...
How data and AI are unlocking South Africa’s next mineral frontier
IT in Manufacturing
Data, AI and blockchain are reshaping how mining companies explore, extract and prove the provenance of resources, opening a new frontier for South Africa’s mining sector.
Read more...
Luna Rossa partners with Siemens for 38th America’s Cup
Siemens South Africa
IT in Manufacturing
Siemens details how Luna Rossa is using digital engineering and simulation tools, from CAD to structural optimisation, to design a faster yacht for the 38th America’s Cup.
Read more...
AI is raising South Africa’s cybersecurity stakes
IT in Manufacturing
As AI accelerates both the sophistication and scale of cyber threats, South African organisations face significant gaps in cloud security, data governance and identity management that need to be addressed before AI capabilities are further embedded into business operations.
Read more...
How modern EAM is becoming the driver of productivity, resilience and sustainability in mines
Schneider Electric South Africa
IT in Manufacturing
Modern enterprise asset management is turning maintenance from a routine function into a strategic priority, helping mines extend the life of ageing infrastructure while improving productivity and safety.
Read more...
Physical AI solution with potential to transform South African manufacturing
IT in Manufacturing
NTT DATA and Hyster-Yale Materials Handling have deployed physical AI in an industrial assembly environment, embedding intelligence into production workflows to improve quality assurance and cut deployment timelines significantly.
Read more...