🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
•🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
•🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
•🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
•🍏 iOS / Mac OSDas E-Book der Woche: Dieses Mal „Inspektor Takeda und der schöne Schein“ für 1,99 Euro mitnehmen(07.09.2026 um 13:43 Uhr)
•🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)
•🍏 iOS / Mac OSWenn iPhone 18 Pro zu teuer wird: Keynote könnte Apple-Aktie drücken(07.09.2026 um 19:23 Uhr)
•🍏 iOS / Mac OSApple Watch Ultra 4 und Series 12: Diese vier Neuerungen deuten watchOS-Betas an(08.09.2026 um 07:24 Uhr)
•🍏 iOS / Mac OSCode-Leak: Fünf neue Features für die Kamera des iPhone 18 Pro(08.09.2026 um 10:00 Uhr)
•🍏 iOS / Mac OSBericht: John Ternus will offenbar mehr Geld aus dem App Store holen(08.09.2026 um 12:00 Uhr)
•🕵️ SicherheitslückenHak5: Hackers Just Poisoned the Rust Supply Chain | Threat Wire(01.09.2026 um 14:00 Uhr)
•🕵️ SicherheitslückenHak5: Hackers Found a Way Into Humanoid Robots | Threat Wire(04.09.2026 um 15:04 Uhr)
•🔧 AI Nachrichten Bits und so #1021 (Passwort für Laufwerk)(31.08.2026 um 22:15 Uhr)
•🔧 AI Nachrichten Bits und so #1022 (Wie Weißbier)(06.09.2026 um 20:39 Uhr)
•🍏 iOS / Mac OSDas E-Book der Woche: Dieses Mal „Inspektor Takeda und der schöne Schein“ für 1,99 Euro mitnehmen(07.09.2026 um 13:43 Uhr)
•🍏 iOS / Mac OSHue-App 6.0 ist da: das sind die Neuerungen(07.09.2026 um 17:21 Uhr)
•🍏 iOS / Mac OSWenn iPhone 18 Pro zu teuer wird: Keynote könnte Apple-Aktie drücken(07.09.2026 um 19:23 Uhr)
•🍏 iOS / Mac OSApple Watch Ultra 4 und Series 12: Diese vier Neuerungen deuten watchOS-Betas an(08.09.2026 um 07:24 Uhr)
•🍏 iOS / Mac OSCode-Leak: Fünf neue Features für die Kamera des iPhone 18 Pro(08.09.2026 um 10:00 Uhr)
•🍏 iOS / Mac OSBericht: John Ternus will offenbar mehr Geld aus dem App Store holen(08.09.2026 um 12:00 Uhr)
•
1 Tag Serie
📰 IT Security Nachrichten 🕛 vor 9 Jahren 2 Min Lesezeit SECURITY-FEED
An anonymous reader quotes a report from Motherboard: For almost six years, Google knew about the exact technique that someone used to trick around one million people into giving away access to their Google accounts to hackers on Wednesday. Even more worrisome: other hackers might have known about this technique as well. On October 4, 2011, a researcher speculated in a mailing list that hackers could trick users into giving them access to their accounts by simply posing as a trustworthy app. This attack, the researcher argued in the message, hinges on creating a malicious application and registering it on the OAuth service under a name like "Google," exploiting the trust that users have in the OAuth authorization process. OAuth is a standard that allows users to grant websites or applications access to their online email and social networking accounts, or parts of their accounts, without giving up their passwords. "Imagine someone registers a client application with an OAuth service, let's call it Foobar, and he names his client app 'Google, Inc.'. The Foobar authorization server will engage the user with 'Google, Inc. is requesting permission to do the following,'" Andre DeMarre wrote in the message sent to the Internet Engineering Task Force (IETF), the independent organization responsible for many of the internet's operating standards. "The resource owner might reason, 'I see that I'm legitimately on the https://www.foobar.com/ site, and Foobar is telling me that Google wants permission. I trust Foobar and Google, so I'll click Allow,'" DeMarre concluded. As it turns out, DeMarre claims he warned Google directly about this vulnerability in 2012, and suggested that Google address it by checking to see ensure the name of any given app matched the URL of the company behind it. In a Hacker News post, DeMarre said he reported this attack vector back then, and got a "modest bounty" for it. Port 8095 Engine
Wie bewertest du diesen Beitrag?
1 Klick Feedback Teilen mit Netzwerk & Team:
Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf „ Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum 🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Tipp: Mit Pfeiltasten [ ← ] und [ → ] blättern
🔖 Gespeicherte Artikel
📂
Keine gespeicherten Artikel vorhanden.
📂 News
⏱️ 3 Min
vor 10 Min
Artikeldaten werden geladen...
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit
Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.
Nächster Beitrag
🤖
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster:
Security Explorer
👥 Match:
lädt…
📡 Aktivitäten deiner Analysten
lädt…
💡 Neues Thema oder Eilmeldung einreichen
Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.
SOCIAL SHARE CARD GENERATOR