News

An attack flow that combines API flaws within "log in with" implementations and Web injection bugs could affect millions of websites.
Analysis of The Attacker’s Behavior GitHub analysis the incident include that the attackers authenticated to the GitHub API using the stolen OAuth tokens issued to accounts Heroku and Travis CI.