Credit:
At this point we're unsure of the cause: Access could have been gained through previous phishing schemes. However, one factor points to a likely suspect: All the tweets are posted via "API," meaning the spammers do not have direct access to the accounts. Rather, there's likely some third-party application that's been compromised (or a rogue one permitted by the users) that's pushing spam tweets.
Suffice it to say: If your friends start tweeting links to diet sites tonight, don't click the links!
We'll let you know when we learn more.
Thanks to Ike Pigott for the heads-up.
UPDATE: The Sophos blog has written about the attacks too.
Credit: