⤷ Title: OAuth Login Bypasses & Account Linking Chaos — A Bug Bounty Adventure
════════════════════════
𐀪 Author: Sohan
════════════════════════
ⴵ Time: Thu, 14 Aug 2025 17:22:53 GMT
════════════════════════
⌗ Tags: #oauth_security #account_takeover #ethical_hacking #bug_bounty #authentication_bypass
════════════════════════
𐀪 Author: Sohan
════════════════════════
ⴵ Time: Thu, 14 Aug 2025 17:22:53 GMT
════════════════════════
⌗ Tags: #oauth_security #account_takeover #ethical_hacking #bug_bounty #authentication_bypass
Medium
OAuth Login Bypasses & Account Linking Chaos — A Bug Bounty Adventure
During a routine bug bounty hunt, I stumbled upon an OAuth login flow behaving like it had a mind of its own. Two related quirks made me…
⤷ Title: Zero-Click Threat: New Attacks Turn AI Browsers into Google Drive Wipers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:27:00 +0000
════════════════════════
⌗ Tags: #Malware #AI browser #data loss #Google Drive Wiper #HashJack #OAuth Security #Perplexity Comet #Prompt Injection #Zero_Click Attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 08 Dec 2025 04:27:00 +0000
════════════════════════
⌗ Tags: #Malware #AI browser #data loss #Google Drive Wiper #HashJack #OAuth Security #Perplexity Comet #Prompt Injection #Zero_Click Attack
Penetration Testing Tools
Zero-Click Threat: New Attacks Turn AI Browsers into Google Drive Wipers
Researchers at Striker STAR Labs have detailed a new attack against agent-based browsers that can turn an ordinary
⤷ Title: The AI Weak Link: How a Third-Party Breach Exposed Vercel Customer Secrets
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 09:17:43 +0000
════════════════════════
⌗ Tags: #Data Leak #API Keys #cloud security #Context.ai #Cybersecurity 2026 #data breach #Environment Variables #Mandiant #Next.js #OAuth Security #supply chain attack #Vercel
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 21 Apr 2026 09:17:43 +0000
════════════════════════
⌗ Tags: #Data Leak #API Keys #cloud security #Context.ai #Cybersecurity 2026 #data breach #Environment Variables #Mandiant #Next.js #OAuth Security #supply chain attack #Vercel
Penetration Testing Tools
The AI Weak Link: How a Third-Party Breach Exposed Vercel Customer Secrets
The month of April concluded for the American firm Vercel with a distressing incident that precipitously transcended the
⤷ Title: They Closed It as N/A. Then They Silently Patched It. Here’s The Full Story.
════════════════════════
𐀪 Author: $cr1p7 k!ddi3
════════════════════════
ⴵ Time: Fri, 29 May 2026 02:55:46 GMT
════════════════════════
⌗ Tags: #open_redirect #optional_chaining #critical #bug_bounty #oauth_security
════════════════════════
𐀪 Author: $cr1p7 k!ddi3
════════════════════════
ⴵ Time: Fri, 29 May 2026 02:55:46 GMT
════════════════════════
⌗ Tags: #open_redirect #optional_chaining #critical #bug_bounty #oauth_security
Medium
🔴 They Closed It as N/A. Then They Silently Patched It. Here’s The Full Story.
A Critical P1 Bug Chain on a Fintech Platform — Open Redirect → OAuth Token Theft → Full Account Takeover | Intigriti Disclosure