/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Password hack of vBulletin.com fuels fears of in-the-wild 0-day attacks

Update:On Monday afternoon, vBulletin Technical Support Lead Wayne Luke issued a statement that said:  —  “Given our analysis of the evidence provided by the Inject0r team, we do not believe that they have uncovered a 0-day vulnerability in vBulletin.

Ars Technica Dan Goodin

Context & Ripple Effects

The Inject0r team has broken into vBulletin.com itself and exposed user passwords, a confirmed breach of the very company whose forum software thousands of sites run. The team's implied claim of an in-the-wild 0-day remains unconfirmed, and vBulletin Technical Support Lead Wayne Luke has gone on record denying that any 0-day was uncovered.

The story traveled fast and wide on November 18, 2013 — picked up same-day by Krebs on Security, Computerworld, Malwarebytes Unpacked, and The Inquirer — which matters because the dispute is now being adjudicated in public before any independent technical confirmation exists. Anxiety over hacks of mainstream publishing platforms is not new either; bloggers were voicing the same unease back when Scobleizer wrote in 2009 about no longer feeling safe on WordPress after hackers broke in.

First-order effects

  • Operators running vBulletin forums must treat the leaked vBulletin.com passwords as live credentials, since password reuse makes every exposed account a potential entry point into customer sites.
  • Wayne Luke's statement commits vBulletin Technical Support to a public position — no 0-day — so the company's own analysis of the Inject0r team's evidence, not third-party verification, is what customers have to rely on.

Second-order effects

  • Rival forum and CMS vendors gain a competitive opening with administrators who now have to weigh whether vBulletin's denial holds up against whatever evidence the Inject0r team published.
  • Security outlets like Krebs on Security and Malwarebytes become the de facto arbiters: their same-day coverage shapes whether the community reads this as routine credential theft or as proof of an exploitable flaw.

Third-order effects

  • The episode follows a structural pattern in web-platform security: an attacker breach doubles as an unverified vulnerability claim, and the vendor's rebuttal — not independent confirmation — becomes the load-bearing fact, raising the stakes on how much weight buyers give official vendor statements.

The trend: Forum-software security disputes are increasingly fought out in public within hours — attacker claims, vendor denials, and broad syndication set the narrative well before any technical verdict arrives.