GoPlus: Meta account recovery feature exposed to high-risk design flaws, which could directly leak users' sensitive information
GoPlus posted on platform X that the Meta account recovery feature has been exposed to a high-risk design flaw, which could directly leak users' phone numbers, email addresses, and PII (Personally Identifiable Information). Attackers only need to input the META username without any login or verification to directly obtain the complete PII linked to the user, such as email addresses and phone numbers. This could pose significant risks to users, including: large-scale phishing attacks, SIM card swapping attacks, account takeover and identity theft, and targeted social engineering attacks.
Recommendations: Remove or change the leaked email/phone number as a recovery method; modify related account passwords and enable 2FA; do not click on any emails or messages related to "account anomalies," "verification," or "password reset"; set up multi-channel verification, which can be verified through official documents or other official social media channels.
You may also like

Paul Graham: How to Make a Billion Dollars

If the AI bubble has already burst, who will truly remain?

Morning Report | Prediction market platforms like Kalshi and Polymarket jointly sue Kentucky over 14.25% trading tax; Bridgewater founder discusses decision-making in the AI era: principled thinking should run parallel to AI, human insight remains irre...

What is the connection between Huang Zheng of Pinduoduo and blockchain?

The other side of Musk's trillion-dollar fortune: 85% cannot be sold

The U.S. government prohibits foreigners from using Fable 5, Anthropic issues a rebuttal

Citibank releases "2030 Asset Tokenization Market Outlook": 6 major trends may create a $8.2 trillion market

The trillion-dollar valuation test: Are the three major super IPOs a celebration for tech stocks or a nightmare for the crypto market?

Morning Report | Digital Asset completes $355 million financing led by a16z Crypto; Meta completes operational separation from Manus

a16z Crypto Partner: Cash flow is the moat

Cryptocurrency market makers collectively seek change as it becomes increasingly difficult to make money

How TradeXYZ, xStocks, and Alpaca break down the SpaceX IPO into three different strategies

$75 billion in risk asset redistribution: How will SpaceX's IPO affect U.S. stocks and Bitcoin?

Why Is BlackRock Investing $5 Billion in the SpaceX IPO?

Morning News | CME Group launches Nasdaq Cryptocurrency Index futures; Asset management giant Janus Henderson strategically invests in Ethena

Bitcoin Layer 2 Network Botanix: Why Did We Choose to Dissolve?

Why did Oracle deliver the strongest financial report in history, yet its stock price fell?




