Hackers are abusing a Google OAuth endpoint to hijack user sessions.

“Millions each and every month” could be affected, according to CloudSEK researcher Pavan Karthick M. You may have just changed your password, but an exploit using an undocumented Google OAuth endpoint to allow continual account access—even if the user changes their password—might make you feel like changing it again. That’s according to research from securityContinue reading “Hackers are abusing a Google OAuth endpoint to hijack user sessions.”