A vulnerability in Twitter’s code was recently discovered that allows users to game the algorithm with mass blocking actions from large numbers of accounts, in an effort to suppress specific users showing up in people’s feeds — essentially, it allows bot-created “shadow bans” in the parlance of social media censorship critics.
Now, the flaw has been assigned a CVE number as an officially recognized security vulnerability: CVE-2023-29218.
By infosecbulletin
/ Wednesday , July 1 2026
Cybersecurity researchers have warned of a "massive, ongoing, automated password spray attack" aimed at Microsoft's Azure command-line interface (CLI), compromising...
Read More
By infosecbulletin
/ Wednesday , July 1 2026
Chrome 151 has a new update that fixes 382 security problems. This includes 15 critical issues that could allow attackers...
Read More
By infosecbulletin
/ Wednesday , July 1 2026
Apple released security updates on Monday for iOS, macOS, and Safari. These updates fix more than thirty issues, including four...
Read More
By infosecbulletin
/ Tuesday , June 30 2026
Attackers are now using a flaw (called CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial app, according to the security...
Read More
By infosecbulletin
/ Tuesday , June 30 2026
WhatsApp is about to release a big update that may change how people communicate on the app. Soon, users can...
Read More
By infosecbulletin
/ Monday , June 29 2026
The Linux Foundation said on Thursday that they are starting a new project to fix flaws in open source software...
Read More
By infosecbulletin
/ Sunday , June 28 2026
KDDI Corporation, a Japanese telecom company, revealed a data breach. Hackers got into one of its email systems that five...
Read More
By infosecbulletin
/ Sunday , June 28 2026
Two Asian AI companies have released new models this week that compete with Anthropic’s recently limited Mythos and Fable models,...
Read More
By infosecbulletin
/ Saturday , June 27 2026
Polymarket is a platform for prediction markets using cryptocurrency. It lets users bet on what might happen in real-life events...
Read More
By infosecbulletin
/ Saturday , June 27 2026
Anthropic said that Claude Mythos 5, its strongest AI security model, will be sent back to some U.S. orgs that...
Read More
“The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arranging for multiple Twitter accounts to coordinate negative signals regarding a target account, such as unfollowing, muting, blocking, and reporting, as exploited in the wild in March and April 2023,” the MITRE CVE entry explained.
The vulnerability was first flagged by infosec researcher Federico Andres Lois after analyzing Twitter’s source code, which was leaked to the public and later posted on GitHub by Twitter as part of its commitment to transparency.
The bug means that botnet armies have the ability to game the algorithm with mass blocks, mutes, abuse reports, spam reports, and unfollows to drive down the number of times specific accounts show up in Twitter’s recommendation engine.
“The current implementation allows for coordinated hurting of account reputation without recourse,” Lois wrote in his disclosure. “Any other time I would just report this information using a vulnerability channel, but given that this is already popular knowledge there is no use to do so.”
The vulnerability has since been discovered by others, prompting a cryptic, yet splashy, response from Twitter CEO Elon Musk.
“Who is behind these botnets?” Musk tweeted. “Million dollar bounty if convicted.”