Did you think XSS is dead? So did we...
We couldn't be more wrong.
XSS is back with a vengeance! 💥
Combined with OAuth, the Salt-Labs team performed a full account takeover on several major online platforms.
https://t.co/yDA4sLMzBR
#XSS#OAuth#cybersecurity#APISec#infosec
Hey @elonmusk, our team at Salt Labs just released some very concerning security issues in the ChatGPT ecosystem, which may put a lot of data for a lot of users at risk.
Time for OpenAI to step up their security game, don't you think?
Full report: https://t.co/0YCOUIxqT9
Check out our latest research. This time, flaws in GenAI ecosystems and several issues in ChatGPT and its integrated plugins.
Kudos, @AviadCarmel, for this wonderful research.
https://t.co/JAZtDlKOcS
Just discovered a full account takeover on https://t.co/9dAKCEpkrV, https://t.co/3b6VWzGVsC and more using a new OAuth attack technique.
This is the last part of the OAuth trilogy; in total, we could take over 1+ BILLION accounts!
https://t.co/TRCljIp6iB
#OAuth#hacking
Down the OAUth rabbit hole we go...
This time it's a framework issue potentially affecting hundreds of online services, including sites like Codecademy and others...
More exciting targets are coming next... stay tuned and secure your OAuth implementations!
https://t.co/SKik65Wf9h
@SaltSecurity@SaltSecurity's contribution, beyond the sponsorship, warms our hearts.
A big shoutout to @ynvb, who contributed ideas and use cases that were quoted in the latest addition.
💖