Security News > 2021 > June > NewsBlur Restores Service After Hacker Wipes Database
Personal news reader NewsBlur was down for several hours last week after a hacker managed to wipe the service's database.
The hacker was able to gain access to the database while the RSS reader was being transitioned to Docker, which circumvented some firewall rules and opened the NewsBlur MongoDB database to the public.
Within roughly three hours, NewsBlur founder Samuel Clay said, the hacker was able to copy the database and delete the original.
"When I switched to a new MongoDB server, a hacker deleted all of NewsBlur's mongo data and is now holding NewsBlur's data hostage. I'm dipping into a backup from a few hours ago and will keep you all updated," he noted in a message on the NewsBlur main page.
Right before transitioning to Docker, Clay shut down the original primary MongoDB cluster, which remained untouched during the attack.
Clay blames the unauthorized access to the database to a change that Docker made in the UFW firewall.