Zapier fixes bug chain that researchers say risked widespread account takeover
ID: 46fa59aa-043e-5dc0-9001-cf6c10150984
STIX ID: report--46fa59aa-043e-5dc0-9001-cf6c10150984
Feed Name: CyberScoop
Security researchers from Token Security chained together five separate weaknesses in Zapier that could have allowed an attacker with only a free account to recover discarded credentials, access internal storage of private software images (including a publishing key), push malicious updates to code running in every logged-in user’s browser, and then act on behalf of users across thousands of connected services; Token Security reported the issues, Zapier remediated them within weeks, paid the bug bounty, and there is no evidence of prior exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
