logo

LinkedIn 0day Vulnerability Puts Your Data at Risk

ID: 3e05c91a-777c-578c-8daa-ae1fea285212

STIX ID: report--3e05c91a-777c-578c-8daa-ae1fea285212

Feed Name: Zimperium Blog

Threat Score
70/100

Date Published: 2014-06-18

Date Updated: 2026-05-01

...
...

Zimperium publicly discloses that LinkedIn's web and mobile site traffic can be downgraded from HTTPS to HTTP via SSL-stripping MITM attacks, allowing attackers to capture credentials, session cookies, messages, connections and perform full account takeover; the advisory includes step-by-step reproduction using the zANTI toolkit, evidence of broad exposure, a vendor disclosure timeline showing delayed remediation, and interim mitigation guidance (enable HTTPS-only setting).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.