Cybersecurity giant was hit by vBulletin attack

User Forum
(Image credit: Comodo)

An anonymous researcher recently disclosed a zero-day in the popular internet forum software vBulletin and the cybersecurity firm Comodo has now come out and said that its own forum was hacked.

Ironically enough, news of the hack was disclosed in a forum post that confirmed a hacker had exploited the vulnerability in vBulletin to gain access to the database of the cybersecurity giant's forum.

The vulnerability requires little skill to exploit and an attacker can use it to remotely run malicious code on a vulnerable forum.

However, in this case the attacker used the exploit to steal information, including user names and email addresses, from the user database of Comodo's forum.

Comodo hack

Exploit code for the vBulletin vulnerability was released on September 23 and two days later, the company released patches for its forum software.

However, despite claiming that it takes “security very seriously” in its disclosure, Comodo failed to immediately patch its forum software and four days after the patches were released, its forum was hacked.

In its disclosure, Comodo provided more information on exactly what information the attackers behind the hack were able to obtain, saying:

“An unknown attacker exploited the recently discovered vBulletin vulnerability and potentially gained access to the forums database. Our investigations are ongoing to determine what data, if any, has been accessed. User accounts on the forums contain information such as username, name, e-mail address, last IP used to access the forums and if used, potentially some social media usernames in very limited situations. All user passwords in the database were stored encrypted. Comodo forums currently have approximately 245,000 registered users.”

There have certainly been more severe data breaches but this one is particularly embarrassing given that as a cybersecurity company, Comodo should have known better than to put off installing the latest security patches.  

Via TechCrunch

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)