Topic: access tokens

  • Hijacked OAuth Apps: Your Cloud's Secret Backdoor

    Hijacked OAuth Apps: Your Cloud's Secret Backdoor

    Cybercriminals exploit internal OAuth applications to create persistent backdoors in corporate cloud systems, bypassing security measures like password resets and multi-factor authentication. Attackers deceive users into approving malicious OAuth apps or compromise admin accounts to create truste...

    Read More »
  • Open-Source Security Scanner for GitHub & GitLab

    Open-Source Security Scanner for GitHub & GitLab

    Legitify is an open-source scanner that audits GitHub and GitLab environments to identify security misconfigurations and policy violations, helping prevent software supply chain attacks. The tool performs comprehensive checks across five key areas, including organization settings and repository s...

    Read More »