Twilio: The Code They Could Relay
Impossible d'ajouter des articles
Échec de l’élimination de la liste d'envies.
Impossible de suivre le podcast
Impossible de ne plus suivre le podcast
-
Lu par :
-
De :
In August of 2022 a text about an expired password reached employees at Twilio, the company whose plumbing sends other apps' verification codes. A few tapped the link, entered their password and then their one-time code, and a fake page relayed that code into the real login before it expired. Through Twilio the attackers reached data about its customers, including roughly nineteen hundred users of the messenger Signal, whose phone numbers or verification codes were exposed; Signal itself was not breached. The same campaign, 0ktapus, hit more than a hundred and thirty organizations. Two weeks earlier it hit Cloudflare, where three employees entered their credentials and nobody got in, because a physical security key will not answer a look-alike address.