X app approvals can bypass password and 2FA, security thread warns
eyishazyer · x · 2026-09-19
A security thread on X account weaknesses highlights a documented phish: in September 2025, Zak Cole showed a DM phish where the preview displayed a real t.co link over a lookalike domain, followed by a genuine X consent screen for a fake Calendar app using Cyrillic lookalike letters — approving it reportedly bypassed password and 2FA.
Other points:
- Consent screens range from read-only to read/write/DMs, and the top tier can send, read and delete DMs; revoke unknown apps under Security and account access > Apps and sessions
- Password changes log out sessions but leave delegates in place; only the owner controls password, phone and login settings — check X Delegate after a scare
- Logging out may leave cached DMs on the device
Related event: X OAuth Phishing Can Bypass 2FA and Access DMs(2 posts)→
More from Safety
- Every AI agent needs a human sponsor liable for its actions, argues tech commentator — binarybits · 2026-09-19
- Sovereign AIs may be impossible to regulate, argue researchers — leaving 'nuisance' path open — binarybits · 2026-09-19
- Ex-DOJ antitrust chief Kanter tells Decoder why AI labs don't need an antitrust exemption for safety — The Verge AI · 2026-09-19
- Social engineering, not hacking, is ASI's likeliest escape route from secure labs — ronbodkin · 2026-09-19
- Gary Marcus: Dario picked auditors with ties to Anthropic and hasn't slowed down at all — GaryMarcus · 2026-09-19
- AI-generated video shows famous actress interviewing massacre survivors — blm1973 · 2026-09-19