Update 2: The Twitter emergency is over! Del Harvey, lead at Twitter’s Trust and Safety team has given the homepage the all clear: “The XSS attack should now be fully patched and no longer exploitable. Thanks, those reporting it.”
Update: Twitter has released a statement (via its @safety Twitter account). It says: “We’ve identified and are patching a XSS attack; as always, please message @safety if you have info regarding such an exploit.” Original story follows…
The Twitter homepage has been taken over by gigantic letters, blacked out tweets and malevolent rainbow messages. An exploit that allows tweets to use the ‘onMouseOver” JavaScript command is behind the problem. If you visit Twitter.com and haven’t got new Twitter yet, moving your mouse over those tweets automatically reposts messages or redirects you to other websites. Read on for details on how to keep safe during this minor Twitter apocalypse…
Read more