Navigation X
ALERT
Click here to register with a few steps and explore all our cool stuff we have to offer!



   3051

GitHub says hackers breached dozens of organizations using stolen OAuth access tokens

by Intellect - 19 April, 2022 - 03:44 PM
This post is by a banned member (Intellect) - Unhide
Intellect  
Infinity
27
Posts
11
Threads
2 Years of service
#1
Cloud-based repository hosting service GitHub on Friday revealed that it discovered evidence of an unnamed adversary capitalizing on stolen OAuth user tokens to unauthorizedly download private data from several organizations.

"An attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including NPM," GitHub's Mike Hanley disclosed in a report.

OAuth access tokens are often used by apps and services to authorize access to specific parts of a user's data and communicate with each other without having to share the actual credentials. It's one of the most common methods used to pass authorization from a single sign-on (SSO) service to another application.

Full article here.
This post is by a banned member (TimeChangeEverything) - Unhide
40.926
Posts
13.755
Threads
5 Years of service
#2
Damn
[Image: 81QoXii.gif]
[Image: PUm4fxA.gif]
[Image: LuLwraI.gif]

 
                                                      
Above Services are Paid Advertisement
This post is by a banned member (Kr4t0s) - Unhide

Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
or
Sign in
Already have an account? Sign in here.


Forum Jump:


Users browsing this thread: 1 Guest(s)