Loading...
Loading...
Browse all stories on DeepNewz
VisitWhich sector will be most affected by OAuth flaw by December 31, 2025?
Tech startups • 25%
Financial services • 25%
Healthcare • 25%
Other • 25%
Reports from cybersecurity firms or major news outlets
Google OAuth Flaw Exposes 6 Million Americans via Defunct Domains
Jan 16, 2025, 06:07 AM
A critical vulnerability in Google's OAuth authentication system has exposed millions of accounts to potential compromise. The flaw allows attackers to exploit defunct domains of failed startups to recreate email accounts of former employees. Using these accounts, attackers can gain unauthorized access to various SaaS platforms, including HR systems, communication tools, and other sensitive services. The vulnerability affects approximately 6 million Americans, particularly those who have worked for startups. The issue stems from Google's reliance on domain ownership for authentication, which does not account for domain ownership changes. Google initially classified the issue as 'working as intended' before reopening the case, paying a bounty for the disclosure, and acknowledging the need for a fix. Security experts have proposed the addition of immutable identifiers to Google's OpenID Connect claims to address the flaw. However, the vulnerability remains unresolved, leaving millions of accounts at risk.
View original story
Healthcare • 25%
Other • 25%
Financial • 25%
Technology • 25%
Bitcoin • 25%
Ethereum • 25%
Dogecoin • 25%
Other • 25%
Pharmaceutical companies • 25%
Hospitals • 25%
Insurance companies • 25%
Technology vendors • 25%
Technology • 25%
Healthcare • 25%
Government • 25%
Financial • 25%
Technology • 25%
Banking • 25%
Healthcare • 25%
Retail • 25%
Retail • 25%
Government • 25%
Healthcare • 25%
Finance • 25%
Retail • 25%
Travel • 25%
Online services • 25%
Other • 25%
Healthcare • 25%
Finance • 25%
Energy • 25%
Government • 25%
Entertainment • 25%
Politics • 25%
Media • 25%
Other • 25%
Government • 25%
Telecommunications • 25%
Financial Services • 25%
Healthcare • 25%
Education • 25%
Finance • 25%
Retail • 25%
Healthcare • 25%
Foreign Adversary Involvement • 25%
Cause Unidentified • 25%
Internal Security Lapses • 25%
Data Broker Involvement • 25%
No • 50%
Yes • 50%
Multi-factor authentication • 25%
Other • 25%
Immutable identifiers in OpenID Connect • 25%
Enhanced domain ownership checks • 25%