Ancestors

Toot

Written by Rob Flickenger ⚡️ on 2025-01-15 at 14:32

Did you ever use Google to log into a website from a domain that no longer exists (think HR systems, LinkedIn, or just about anything with a “sign in with Google button”).

Remove it from your accounts immediately, if you can.

If you have a domain that’s about to expire that ever used Google for sign-in, clean those accounts up now.

Same goes for any third party SSO. If you no longer control the domain, expect to be impersonated.

https://thehackernews.com/2025/01/google-oauth-vulnerability-exposes.html?m=1

=> More informations about this toot | More toots from hackerfriendly@mas.to

Descendants

Written by Raasclart! inpc on 2025-01-15 at 14:33

@hackerfriendly cool!

=> More informations about this toot | More toots from inpc@go.mxtthxw.art

Written by Rob Flickenger ⚡️ on 2025-01-15 at 14:36

@inpc I’ve seen friends get compromised this way. Not surprised to see it getting more attention. It’s an easy own.

=> More informations about this toot | More toots from hackerfriendly@mas.to

Written by Raasclart! inpc on 2025-01-15 at 14:50

@hackerfriendly have passed the article to some people I think should know. Many thanks.

=> More informations about this toot | More toots from inpc@go.mxtthxw.art

Proxy Information
Original URL
gemini://mastogem.picasoft.net/thread/113832855188608316
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
262.16578 milliseconds
Gemini-to-HTML Time
1.018504 milliseconds

This content has been proxied by September (3851b).