Personal news reader NewsBlur was down for several hours last week after a hacker managed to wipe the service’s database.
The hacker was able to gain access to the database while the RSS reader was being transitioned to Docker, which circumvented some firewall rules and opened the NewsBlur MongoDB database to the public.
Within roughly three hours, NewsBlur founder Samuel Clay said, the hacker was able to copy the database and delete the original.
“When I switched to a new MongoDB server, a hacker deleted all of NewsBlur’s mongo data and is now holding NewsBlur’s data hostage. I’m dipping into a backup from a few hours ago and will keep you all updated,” he noted in a message on the NewsBlur main page.
Right before transitioning to Docker, Clay shut down the original primary MongoDB cluster, which remained untouched during the attack. Clay immediately started taking a snapshot of this primary to restore the service, and was able to bring all back online approximately ten hours later.
Clay blames the unauthorized access to the database to a change that Docker made in the UFW firewall.
“When I containerized MongoDB, Docker helpfully inserted an allow rule into iptables, opening up MongoDB to the world. So while my firewall was ‘active’, […] MongoDB was open to the world,” Clay explains.
The issue is not new. In fact, it has been around for years, requiring admins to modify the UFW configuration file to add specific rules for Docker.
Related: Old Vulnerability Exploited to Hack, Wipe WD Storage Devices
Related: Cybersecurity Firm Exposes Breach Database Containing 5 Billion User Records

More from Ionut Arghire
- Former Ubiquiti Employee Who Posed as Hacker Pleads Guilty
- Atlassian Warns of Critical Jira Service Management Vulnerability
- Exploitation of Oracle E-Business Suite Vulnerability Starts After PoC Publication
- Google Shells Out $600,000 for OSS-Fuzz Project Integrations
- F5 BIG-IP Vulnerability Can Lead to DoS, Code Execution
- Flaw in Cisco Industrial Appliances Allows Malicious Code to Persist Across Reboots
- HeadCrab Botnet Ensnares 1,200 Redis Servers for Cryptomining
- Malicious NPM, PyPI Packages Stealing User Information
Latest News
- Former Ubiquiti Employee Who Posed as Hacker Pleads Guilty
- Cyber Insights 2023: Venture Capital
- Atlassian Warns of Critical Jira Service Management Vulnerability
- High-Severity Privilege Escalation Vulnerability Patched in VMware Workstation
- Exploitation of Oracle E-Business Suite Vulnerability Starts After PoC Publication
- China Says It’s Looking Into Report of Spy Balloon Over US
- GoAnywhere MFT Users Warned of Zero-Day Exploit
- Google Shells Out $600,000 for OSS-Fuzz Project Integrations
