X OAuth Phishing Can Bypass 2FA and Access DMs

A disclosed phishing case showed fake X authorization pages exploiting t.co link previews, while X's top third-party app permission tier can read, send and delete DMs. Users are advised to audit authorized apps in account security settings.

2026-09-19 ~ 2026-09-19 · 2 related posts