A researcher named Remy found a critical OAuth vulnerability during a YesWeHack bug bounty, exposing sensitive user data due to misconfiguration. This flaw granted unrestricted access to personal and financial information. The unnamed company fixed the issue within 24 hours. The incident underscores the importance of secure OAuth practices and adherence to the principle of least privilege.

‘China has almost doubled their aggression in cyber’: Kevin Mandia and Nicole Perlroth warn organizations aren’t waking up to growing APT threats
Amid state-backed threats and budget cuts affecting cybersecurity teams, experts are advising organizations to monitor their environments more vigilantly. Enhanced vigilance is essential to safeguard