Yahoo Jobs site could have fallen to data hack
The threat of a SQL injection hack had been hanging over Yahoo's recruitment website.

Security researchers have said that the Yahoo jobs site was potentially open to a SQL injection flaw.
Data security company Imperva said that the Blind SQLi' problem meant that the personal information of people could have been compromised.
Amichai Shulman, chief technology officer for Imperva, said in a statement that data could have been taken and traded on online fraud forums. He explained that the SQL injection hack could have harvested private data, with forums acting as an auction or exchange.
"If the potential problem is allowed to continue for any length of time, then the risk of a hacker attack rises as a result," he said.
"SQL injection is a major thorn in the side for the web site hosting community. It can be tackled with careful research and high levels of security. Unfortunately, some site operators overlook this simple fact as high risk."
Yahoo had not responded to IT PRO's request for comment at the time of publication, but Imperva claimed that the company had been contacted, and had already deployed a fix to resolve the issue.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
The worst hacks of all time
In-depth Yahoo, LinkedIn, Facebook, here is a quick guide to some of the biggest data breaches in history
By Rene Millman Published
-
Yahoo handed £250,000 fine over 2014 data breach
News ICO punishes Yahoo's UK arm for failing to protect 515,000 Brits
By Adam Shepherd Published
-
Canadian pleads guilty to Yahoo hack
News Karim Baratov was paid by Russian security agents to break into Yahoo accounts in 2014
By Dale Walker Published
-
Russia denies it's responsible for Yahoo hack
News The Kremlin said there's "absolutely no question of any official involvement by any Russian agency"
By Clare Hopping Published
-
Verizon knocks $350m off Yahoo deal
News Yahoo will also need to pay half of any liabilities incurred as a result of massive data breach
By Clare Hopping Published
-
Yahoo email scandal could derail Safe Harbour replacement
News Reports of mass email surveillance prompt fears of rights infringements
By Jane McCallion Published
-
Individual sues Yahoo over data breach
News New York man has accused Yahoo of gross negligence
By Clare Hopping Published
-
Yahoo hack: what your business needs to know - and why you shouldn't panic
Analysis The Yahoo hack is frightening, but the worst of the attacks are likely already over
By Nicole Kobie Published