X fixes URL blunder that could enable convincing social media phishing campaigns
ID: bcff88b4-76a5-5d37-ab7b-8cf36e5c8e8e
STIX ID: report--bcff88b4-76a5-5d37-ab7b-8cf36e5c8e8e
Feed Name: The Register (Security)
Threat Score
A bug in X's iOS app auto-rewrote instances of "Twitter" inside URLs to "X", producing links that displayed legitimate brand domains (e.g., Netflix.com) while actually resolving to the original, potentially malicious domains (e.g., netflitwitter.com). The behavior persisted for at least nine hours before being reversed; although a proactive user registered a lookalike domain to prevent abuse, the flaw could have enabled phishing, credential theft, or malware delivery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
