logo

Open Redirects: A Forgotten Vulnerability?, (Tue, Feb 24th)

ID: f34d43bf-5017-5f00-83d1-75c64726f543

STIX ID: report--f34d43bf-5017-5f00-83d1-75c64726f543

Feed Name: SANS ISC Diary

Threat Score
35/100

Date Published: 2026-02-24

Date Updated: 2026-04-19

...
...

The report describes an increase in automated scans for open-redirect endpoints observed in honeypots, noting common redirect URL patterns and that most requests originated from a single IP (89.248.168.239) hosted by AS202425 (IP Volume). It explains the risk of open redirects for phishing and OAuth token interception, references OWASP guidance, shows daily request volume growth, and recommends considering blocking the abusive ASN.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.