Nuacht

And while not directly responsible for the exploit, the fact OAuth was chained to the Facebook vulnerability puts a spotlight on this popular security standard and the added risks it brings.
A widespread phishing campaign has targeted nearly 12,000 GitHub repositories with fake "Security Alert" issues, tricking developers into authorizing a malicious OAuth app that grants attackers ...
What is device code phishing, and why are Russian spies so successful at it? Overlooked attack method has been used since last August in a rash of account takeovers.