Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

How we broke exchanges: a deep dive into authentication and client-side bugs

Summary

OtterSec details OAuth misconfigurations that lead to account takeover in exchanges, SDKs and wallets, including Google GSI/FedCM flow quirks and desktop-vs-mobile environment gaps.
Published
Collected

original ↗

Related coverage

back