Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 16, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 16, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 16, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 16, 2025

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025

      Minecraft licensing robbed us of this controversial NFL schedule release video

      May 16, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The power of generators

      May 16, 2025
      Recent

      The power of generators

      May 16, 2025

      Simplify Factory Associations with Laravel’s UseFactory Attribute

      May 16, 2025

      This Week in Laravel: React Native, PhpStorm Junie, and more

      May 16, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025
      Recent

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Hackers Hijack High-Profile TikTok Accounts in Zero-Day Cyberattack

    Hackers Hijack High-Profile TikTok Accounts in Zero-Day Cyberattack

    June 5, 2024

    Malicious actors recently hacked high-profile TikTok accounts of big companies and celebrities and exploited a zero-day vulnerability in TikTok’s direct messaging feature. This TikTok zero-day vulnerability allowed the hackers to take control of accounts without the need for victims to download anything or click on any links.

    For all those who are unaware of what is a zero-day vulnerability, it is a security hole in software that the makers themselves are unaware of. The reason why it’s a prime target of the hackers is that there’s no patch or public information about the flaw.

    The TikTok zero-day vulnerability has impacted and hijacked accounts belonging to CNN, Sony, and Paris Hilton.

    According to the Semaphor, CNN’s account was the first to be compromised last week. Afterward, similar cyberattacks targeted Sony and Paris Hilton’s accounts. To prevent any further misuse, TikTok took these accounts offline.

    How Did the TikTok Zero-Day Vulnerability Occur?

    According to Forbes, which first reported the incident, hackers simply opened a malicious direct message to compromise an account. It was noted that there was no need to download any files or click on any links, making the attack easy to carry out and difficult to detect.

    Alex Haurek who leads TikTok’s security team, responded to Forbes noting, “Our security team is aware of a potential exploit targeting a number of brand and celebrity accounts. We have taken measures to stop this attack and prevent it from happening in the future. We’re working directly with affected account owners to restore access if needed.”

    TikTok has also notified that only a small number of accounts were compromised, but it hasn’t given specific numbers or detailed the vulnerability until they fix it completely.

    Prior Security Issues

    This isn’t the first time TikTok has faced security issues. In August 2022, Microsoft discovered a flaw in TikTok’s Android app that allowed hackers to take over accounts with a single tap. TikTok has also fixed other security bugs that let attackers steal private user information, bypass privacy protections, and manipulate user videos.

    In another example, Apple released a software update to fix a bug in WebKit, which runs Safari and other web apps. This bug could have allowed malicious code to run on affected devices. Apple quickly patched this across all its devices, including iPhones, iPads, Macs, and Apple TV.

    In mid-2023, TikTok was fined £12.7 million by the Information Commissioner’s Office (ICO) for multiple breaches of data protection laws. These include allowing over one million children under 13 to use its platform without parental consent in 2020, contrary to its own terms of service.

    The ICO’s investigation found that TikTok had allowed an estimated 1.4 million UK children under 13 to create accounts and use its platform, despite its rules stating that users must be at least 13 years old.

    This resulted in the unlawful processing of children’s data without proper consent or authorization from their parents or guardians, a requirement under UK data protection law for organizations offering information society services to children under 13. 

    Furthermore, TikTok failed to provide adequate information to its users, especially children, on how their data was being collected, used, and shared in a clear and understandable manner. 

    This lack of transparency made it difficult for users to make informed choices about their engagement with the platform.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCelebrity TikTok Accounts Compromised Using Zero-Click Attack via DMs
    Next Article arielmejiadev/larapex-charts

    Related Posts

    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 17, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2025-40906 – MongoDB BSON Serialization BSON::XS Multiple Vulnerabilities

    May 17, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    CVE-2025-4067 – ScriptAndTools Online-Travling-System Remote File Inclusion Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Attackers Exploit Public .env Files to Breach Cloud and Social Media Accounts

    Development

    Wiping your Android phone? Here’s the easiest way to erase all personal data

    Development

    CVE-2025-29967 – Citrix Remote Desktop Gateway Service Heap Buffer Overflow Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    Artificial Intelligence

    ‘AI Scientist’ performs fully automatic scientific discovery

    August 13, 2024

    Japanese AI research lab Sakana AI has developed The AI Scientist, a framework for fully…

    Type Scale Generator

    January 9, 2025

    St-Jerome Company Targeted in Alleged Ransomware Attack by Everest Group

    April 26, 2024

    OpenAI and Deepmind insiders demand a right to warn, OpenAI Offers a peek Inside the guts of ChatGPT, a new SORA rival, and more!

    June 10, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.