ENS Engineer Uncovers Phishing Exploit in Google Systems
- Nick Johnson, an Ethereum Name Service engineer, identified a phishing campaign.
- The exploit targeted vulnerabilities in Google’s backbone infrastructure.
- A recently patched OAuth flaw was central to the phishing strategy.
- The attack initiated with an email mimicking an official Google alert.
Nick Johnson revealed a phishing campaign exploiting Google’s infrastructure weaknesses, particularly a patched OAuth flaw, using emails that appeared to be from Google.
Source (2.6)https://news.bitcoin.com/ens-lead-developer-reveals-flaw-allowing-phishers-to-mimic-official-google-alerts/?rand=52384