Tumblr hacked?(thisistheverge.tumblr.com) |
Tumblr hacked?(thisistheverge.tumblr.com) |
You just need to change your password and/or see what apps have access ( https://www.tumblr.com/settings/applications ). Maybe clear your browser cookie/cache/etc. to be safe, as well. That's how my friend got rid of that auto-post junk of her Tumblr account.
Tumblr are suggesting you log out/clear cookies if you visited any of the hacked sites
> There is a viral post circulating on Tumblr which begins "Dearest 'Tumblr' users". If you have viewed this post, please log out of all browsers that may be using Tumblr immediately. Our engineers are working to resolve the issue as swiftly as possible. Thank you.
User opens up their dashboard, which displays a post that contains the XSS.
That script then makes a post using the users account to their own blog, further spreading the rogue script.