SECURITYCYBERSCOOP
Zapier fixes bug chain that researchers say risked widespread account takeover
Security researchers at Token Security discovered a chain of five vulnerabilities in Zapier that could have allowed attackers to gain access to millions of user accounts and connected systems without malware or insider access. The flaws, which exploited weaknesses in code execution and credential storage, could have enabled malicious actors to impersonate users and manipulate integrations with third-party services. The vulnerabilities were responsibly disclosed through Zapier's bug-bounty program and have since been patched.
Mentioned