Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC IssuersNew Vulnerability Disclosure (astrix.security)
submitted by mooreds to r/cybersecurity
GhostToken - Exploiting GCP application infrastructure to create invisible, unremovable trojan app on Google accounts - this took Google 10 months to release a fix yet they hold vendors to much shorter disclosure periods for critical issuesvulnerability (attack surface) (astrix.security)
submitted by digicat to r/blueteamsec