Skip to content
The Nexus
DossierENTITY

Token Security

Coverage of Token Security in the Nexus archive.

Earliest in view: May 28 · 13:00 UTCMost recent: May 28 · 13:00 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYMay 28 · 13:00 UTCCYBERSCOOP
    Zapier fixes bug chain that researchers say risked widespread account takeover

    Security researchers at Token Security discovered a chain of five vulnerabilities in Zapier that could have allowed attackers to gain access to millions of user accounts and connected systems without malware or insider access. The flaws, which exploited weaknesses in code execution and credential storage, could have enabled malicious actors to impersonate users and manipulate integrations with third-party services. The vulnerabilities were responsibly disclosed through Zapier's bug-bounty program and have since been patched.