Cybersecurity Firm Comodo Suffers Embarrassing Forum Database Breach
Comodo confirms a hacker exploits a known vBulletin vulnerability to steal personal data from roughly 245,000 forum users. This marks the second major security lapse for the cybersecurity company this year.
Comodo, a company that markets itself as a global leader in cybersecurity solutions, confirms that its forum falls victim to a hacker. The attacker exploits a recently disclosed vulnerability in vBulletin, a popular forum software platform, to remotely execute malicious code and dump the entire user database.
The exploited flaw requires very little skill to leverage, and public exploit code surfaces on September 23. Although vBulletin releases patches just two days later, Comodo fails to apply the updates immediately. Four days after the patches become available, the hacker successfully breaches the forum and steals user data.
The compromised information includes usernames, real names, email addresses, last-used IP addresses, and some social media handles for approximately 245,000 registered users. This embarrassing lapse marks the second security snafu for Comodo this year, following a previous incident where an exposed password granted a researcher access to the company's internal intranet and sensitive files.