Skip to content
The Nexus
SECURITYMay 28 · 13:00 UTCCYBERSCOOPGreg Otto

Zapier fixes bug chain that researchers say risked widespread account takeover

Security researchers at Token Security discovered a chain of five vulnerabilities in Zapier that could have allowed attackers to gain access to millions of user accounts and connected systems without malware or insider access. The flaws, which exploited weaknesses in code execution and credential storage, could have enabled malicious actors to impersonate users and manipulate integrations with third-party services. The vulnerabilities were responsibly disclosed through Zapier's bug-bounty program and have since been patched.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this