Malware

Cybersecurity Company Check Point’s ZoneAlarm Forum Hacked – Attackers Exploited Patched vBulletin 0-Day Flaw

ZoneAlarm forums have been breached, more than 5k users’ details record has been exposed. The details include customers with personal information and IP address.

The ZoneAlarm is an internet security company that offers antivirus and firewall products, the company was acquired by Check Point in March 2004.

ZoneAlarm Forum Hacked

The forum was hacked using patched vBulletin 0-Day vulnerability(CVE-2019-16759) that reported on September 24, 2019. The vBulletin is one of the most popular and widely used forum software which is written in PHP.

VBulletin fixed the vulnerability in two days, on September 26, 2019, the company released patches, it affects versions from 5.0.0 till 5.5.4.

vBulletin is a forum software package based on MySQL and PHP, like other CMS this package used to build Internet forums.

The vulnerability can be exploited by the attacker sending a specially crafted HTTP POST request to execute the arbitrary code in the targeted forum.

This incident occurred due to the lack of patch management. It is a surprise that a leading security company itself running an outdated version of the forum software.

According to the breach report, the file containing 5175 unique records allegedly belonging to ZoneAlarm was found today in public forums.

The exposed data includes hashed passwords, birth dates, and IPs of ZoneAlarm forum users. The company confirms that around 4,500 subscribers with website “forums.zonealarm.com” were affected by the incident.

At the time of writing the website is not active and the company working on it to fix the issue. Users of the forum are recommended to reset the login credentials.

This is not the first time hackers using vBulletin 0-Day to hack forums, earlier another Cybersecurity firm Comodo Security Solutions forum has been hacked using the same exploit.

You can follow us on LinkedinTwitterFacebook for daily Cyber Security and hacking news updates.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago