The massive market transformation this month that some on Wall Street called a "once in a decade opportunity" might have just been a one-off technical move because of taxes.Marketsread more
The Pentagon will deploy U.S. forces to the Middle East on the heels of the attack on Saudi Arabian oil facilities, United States Secretary of Defense Mark Esper announced...Defenseread more
CNBC did a deep dive through the most recent Wall Street research to find stocks that analysts say are underappreciated.Marketsread more
Shares of MasterCard are up 46% this year, and 1120% since 2011, getting a boost from the strong U.S. consumer.Investingread more
CNBC sat in on an "empathy training" at Amazon PillPack's Somerville offices, which is part of new hire orientation.Technologyread more
Trade with China is the 'big unknown' for the Federal Reserve as it decides how best to support the U.S. economy, says Council on Foreign Relations Director of International...Futures Nowread more
Lobbying experts said the visit is likely an attempt to be in lawmakers' ears as they consider legislation that would impact Facebook.Technologyread more
Yardeni Research's Edward Yardeni believes the U.S. economy is picking up steam.Trading Nationread more
Iran's audacious drone and cruise missile attack on Saudi Arabia's oil producing facilities has provided a critical test yet for the Trump administration's foreign policy. A...Politicsread more
Chinese trade negotiators suddenly canceled a visit to meet U.S. farmers after they wrapped up trade talks in Washington this week.Marketsread more
Facebook discovered a security issue that allowed hackers to access information that could have let them take over around 50 million accounts, the company announced Friday.
"This is a very serious security issue, and we're taking it very seriously," said CEO Mark Zuckerberg on a call with reporters.
Facebook shares, which were already down about 1.5 percent before the announcement, extended losses after the disclosure and ended down 2.6 percent.
The company said in a blog post that its engineering team found on Tuesday that attackers identified a weakness in Facebook's code regarding its "View As" feature. Facebook became aware of a potential attack after it noticed a spike in user activity on Sept. 16.
"View As" lets users see what their profile looks like to other users on the platform. This vulnerability, which consisted of three separate bugs, also allowed the hackers to get access tokens — digital keys which let people stay logged into the service without having to re-enter their password — which could be used to control other people's accounts.
Almost 50 million accounts had their access tokens taken, and Facebook has reset those tokens. The company also reset tokens for an additional 40 million accounts who used the "View As" feature in the last year as a precautionary measure, for a total of 90 million accounts. Facebook had 2.23 billion monthly active users as of June 30.
The reset will require these users to re-enter their password when they return to Facebook or access an app that uses Facebook Login. They will also receive a notification at the top of their News Feed explaining what happened.
In addition, the company suspended the "View As" feature while it reviews its security. Facebook said it fixed the issue on Thursday night and has notified law enforcement including the FBI and the Irish Data Protection Commission in order to any address General Data Protection Regulation (GDPR) issues.
Facebook said it has just begun its investigation and has not determined if any information was misused, but the initial investigation has not uncovered any information abuse. The hackers did query Facebook's API system, which lets applications communicate with the platform, to get more user information. The company is not sure if the hackers used that data, nor does it know who orchestrated the hack or where the person or people are based.
The company said there is no need to change passwords. If additional accounts are affected, Facebook said it will immediately reset those users' access tokens. Facebook is doubling the number of employees who are working to improve security from 10,000 to 20,000, the company reiterated.
"Security is an arms race, and we're continuing to improve our defenses," Zuckerberg said. "This just underscores there are constant attacks from people who are trying to underscore accounts in our community."
Zuckerberg addressed the issue in a Facebook post on his account. Read it below: