LinkedIn 0day Vulnerability Puts Your Data at Risk
ID: 3e05c91a-777c-578c-8daa-ae1fea285212
STIX ID: report--3e05c91a-777c-578c-8daa-ae1fea285212
Feed Name: Zimperium Blog
Threat Score
Zimperium publicly discloses that LinkedIn's web and mobile site traffic can be downgraded from HTTPS to HTTP via SSL-stripping MITM attacks, allowing attackers to capture credentials, session cookies, messages, connections and perform full account takeover; the advisory includes step-by-step reproduction using the zANTI toolkit, evidence of broad exposure, a vendor disclosure timeline showing delayed remediation, and interim mitigation guidance (enable HTTPS-only setting).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
