Couverture de Twilio: The Code They Could Relay

Twilio: The Code They Could Relay

Twilio: The Code They Could Relay

Écouter gratuitement

Voir les détails

Offres de saison | 0,99 € par mois pendant les 3 premiers mois

5,99 €/mois par la suite. Des conditions s’appliquent. Annulation mensuelle possible.

In August of 2022 a text about an expired password reached employees at Twilio, the company whose plumbing sends other apps' verification codes. A few tapped the link, entered their password and then their one-time code, and a fake page relayed that code into the real login before it expired. Through Twilio the attackers reached data about its customers, including roughly nineteen hundred users of the messenger Signal, whose phone numbers or verification codes were exposed; Signal itself was not breached. The same campaign, 0ktapus, hit more than a hundred and thirty organizations. Two weeks earlier it hit Cloudflare, where three employees entered their credentials and nobody got in, because a physical security key will not answer a look-alike address.

adbl_web_anon_alc_button_suppression_t1
Aucun commentaire pour le moment