Topic: access tokens
-
Hijacked OAuth Apps: Your Cloud's Secret Backdoor
Cybercriminals exploit internal OAuth applications to create persistent backdoors in corporate cloud systems, bypassing security measures like password resets and multi-factor authentication. Attackers deceive users into approving malicious OAuth apps or compromise admin accounts to create truste...
Read More » -
Open-Source Security Scanner for GitHub & GitLab
Legitify is an open-source scanner that audits GitHub and GitLab environments to identify security misconfigurations and policy violations, helping prevent software supply chain attacks. The tool performs comprehensive checks across five key areas, including organization settings and repository s...
Read More »