[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fgrdxc9xj0vld":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":13,"affectedCountUnit":22,"hasEnglishDescription":4,"contentLocale":23,"availableLocales":24,"translations":26,"severity":29,"dataClasses":30,"description":35,"seoTitle":36,"seoDescription":37,"logoUrl":38,"isVerified":4,"isSensitive":39,"isSpamList":39,"isMalware":39,"company":40},"6aad1fa9928957a5f38a70f9","Grails Forum 2019","Grails Forum Data Breach","grailsforum-2019","grailsforum.co.uk","2019-11-01T00:00:00.000Z","2026-09-18T11:25:28.909Z",null,"Grails Forum vBulletin exploit (CVE-2019-16759)","https:\u002F\u002Fgrails.org\u002F",[15,17,18,19],"https:\u002F\u002Fwww.cve.org\u002FCVERecord?id=CVE-2019-16759","https:\u002F\u002Fsynscan.net\u002F","https:\u002F\u002Fransomlook.io\u002F",88118,"known","unknown","en",[23,25],"tr",{"en":27,"tr":28},{"slug":9},{"slug":9},"Medium",[31,32,33,34],"Email addresses","Usernames","Passwords","IP addresses","\u003Cp>\u003Cstrong>The November 2019 Grails Forum data breach\u003C\u002Fstrong> occurred when unauthorized threat actors breached \u003Cstrong>GrailsForum\u003C\u002Fstrong> (\u003Ccode>grailsforum.co.uk\u003C\u002Fcode>), the premier discussion and technical support community dedicated to the Groovy and Java-based Grails web application framework. The intruder leveraged the critical vBulletin pre-authentication remote code execution vulnerability documented under \u003Cstrong>CVE-2019-16759\u003C\u002Fstrong> to dump the complete member database.\u003C\u002Fp>\u003Ch2>What information was affected in the Grails Forum incident?\u003C\u002Fh2>\u003Cp>The compromised vBulletin database export (\u003Ccode>grailsforum.co.uk._november2019_vB_88834.csv\u003C\u002Fcode>) contains complete account profiles for developers worldwide. The incident compromised records for \u003Cstrong>88,118 unique software engineers and developers\u003C\u002Fstrong>, exposing:\u003C\u002Fp>\u003Cul>\u003Cli>\u003Cstrong>Account Identifiers:\u003C\u002Fstrong> Community usernames.\u003C\u002Fli>\u003Cli>\u003Cstrong>Contact Details:\u003C\u002Fstrong> Verified canonical email addresses.\u003C\u002Fli>\u003Cli>\u003Cstrong>Security Credentials:\u003C\u002Fstrong> Salted MD5 password hashes and accompanying salt strings.\u003C\u002Fli>\u003Cli>\u003Cstrong>Network Telemetry:\u003C\u002Fstrong> User IP addresses recorded upon registration and activity.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>How many accounts were affected?\u003C\u002Fh2>\u003Cp>Strict canonical RFC validation and deduplication confirmed \u003Cstrong>88,118 unique verified email addresses\u003C\u002Fstrong> across 88,834 user table records.\u003C\u002Fp>\u003Ch2>Technical analysis and security risks\u003C\u002Fh2>\u003Cp>The breach was executed via weaponized exploitation of CVE-2019-16759 in the vBulletin forum software. Because software engineers and technology professionals constituted the primary user base, compromised credentials represent an acute threat of automated credential stuffing attacks targeting code repositories (GitHub, GitLab, Bitbucket), CI\u002FCD pipelines, and cloud administration portals.\u003C\u002Fp>\u003Ch2>Recommended actions for affected users\u003C\u002Fh2>\u003Cp>Developers who held accounts on GrailsForum should:\u003C\u002Fp>\u003Cul>\u003Cli>Immediately rotate passwords across any development, email, or infrastructure accounts sharing the forum password.\u003C\u002Fli>\u003Cli>Deploy hardware security keys (FIDO2\u002FWebAuthn) or time-based one-time password (TOTP) authenticators across all code repositories.\u003C\u002Fli>\u003Cli>Monitor authorized OAuth applications and SSH keys on developer services for anomalies.\u003C\u002Fli>\u003C\u002Ful>","Grails Forum Data Breach (88.1 Thousand Reported Records)","Grails Forum Data Breach. 88.1 Thousand reported records are reported. Reported data: Email addresses, Usernames, Passwords. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fgrailsforum.webp",false,{"name":8,"sector":41,"country":42,"website":42,"websiteArchiveUrl":42,"websiteStatus":42,"websiteCheckedAt":13},"Unknown",""]