A vulnerability in Twitter’s code was recently discovered that allows users to game the algorithm with mass blocking actions from large numbers of accounts, in an effort to suppress specific users showing up in people’s feeds — essentially, it allows bot-created “shadow bans” in the parlance of social media censorship critics.
Now, the flaw has been assigned a CVE number as an officially recognized security vulnerability: CVE-2023-29218.
By infosecbulletin
/ Friday , October 9 2026
There was a rise in scanning and remote code execution attempts on video surveillance devices in Ukraine from September 21...
Read More
By infosecbulletin
/ Thursday , October 8 2026
The FBI and U.S. Secret Service released a joint warning about cybersecurity. The warning said that the FortiBleed campaign is...
Read More
By infosecbulletin
/ Wednesday , October 7 2026
Bangladesh's digital payments system remains severely disrupted after a technology conflict forces core card and interbank services offline for millions...
Read More
By infosecbulletin
/ Tuesday , October 6 2026
Atlassian has fixed CVE-2026-21589, a serious flaw in Atlassian Data Center with a score of 9.3. This bug allows an...
Read More
By infosecbulletin
/ Monday , October 5 2026
Citrix has put out emergency security updates for a NetScaler SAML flaw that hackers are using. Known as CVE-2026-88779, this...
Read More
By infosecbulletin
/ Monday , October 5 2026
Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
By infosecbulletin
/ Sunday , October 4 2026
Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
By infosecbulletin
/ Saturday , October 3 2026
CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
By infosecbulletin
/ Friday , October 2 2026
Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
By infosecbulletin
/ Thursday , October 1 2026
Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
“The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arranging for multiple Twitter accounts to coordinate negative signals regarding a target account, such as unfollowing, muting, blocking, and reporting, as exploited in the wild in March and April 2023,” the MITRE CVE entry explained.
The vulnerability was first flagged by infosec researcher Federico Andres Lois after analyzing Twitter’s source code, which was leaked to the public and later posted on GitHub by Twitter as part of its commitment to transparency.
The bug means that botnet armies have the ability to game the algorithm with mass blocks, mutes, abuse reports, spam reports, and unfollows to drive down the number of times specific accounts show up in Twitter’s recommendation engine.
“The current implementation allows for coordinated hurting of account reputation without recourse,” Lois wrote in his disclosure. “Any other time I would just report this information using a vulnerability channel, but given that this is already popular knowledge there is no use to do so.”
The vulnerability has since been discovered by others, prompting a cryptic, yet splashy, response from Twitter CEO Elon Musk.
“Who is behind these botnets?” Musk tweeted. “Million dollar bounty if convicted.”