Close Menu
Computing.net
    Facebook X (Twitter) Instagram
    Computing.netComputing.net
    • News
      1. AI
      2. Crypto
      3. Gaming
      4. Hardware
      5. Security
      6. Software
      7. View All

      Anthropic’s COBOL Automation Tool Triggers IBM Stock Plunge and Crypto Market Decline

      February 24, 2026

      AI Trading Bot Loses $441K in Crypto After Decimal Point Mistake

      February 23, 2026

      Tesla (TSLA) Stock: Goodbye Sedans, Hello Robots in Dramatic Production Shift

      January 29, 2026

      Palantir Technologies (PLTR) Stock: Why Bears May Be Wrong About Valuation Concerns

      January 29, 2026

      SUI Token Rallies 40% Following Major Staking Event and CME Futures Announcement

      May 12, 2026

      Chainlink (LINK) Surges to $10.40 as Network Activity Hits Eight-Month Peak

      May 12, 2026

      Dogecoin Whales Ramp Up Accumulation as DOGE Eyes Critical Breakout Levels

      May 12, 2026

      Bitcoin Holds $81K While Burry Flags Nasdaq Bubble and Oil Surges Past $105

      May 12, 2026

      Hamster Kombat: Unraveling TON’s Gaming Phenomenon

      August 7, 2024

      W-Coin: Exploring the Latest Telegram Tap-to-Earn Phenomenon

      August 7, 2024

      Hamster Kombat: 300 Million Players & Counting, HMSTR Token Airdrop Soon!

      July 31, 2024

      Hamster Kombat Developers Work with TON Team on Airdrop Solution

      July 30, 2024

      Nothing Expands Product Line with New AI Feature & Phone Update

      July 31, 2024

      Security Audit Reveals Concerns in Atari’s Blockchain Game on Base

      August 6, 2024

      SideWinder Group Targets Maritime Facilities in New Cyber Espionage Campaign

      July 30, 2024

      OAuth Implementation Flaw Exposes Millions of Websites to XSS Attacks

      July 30, 2024

      Hamster Kombat Players Face Growing Cybersecurity Threats

      July 25, 2024

      Anthropic’s COBOL Automation Tool Triggers IBM Stock Plunge and Crypto Market Decline

      February 24, 2026

      Cookie Crumble: Google Halts Plans to Eliminate Third-Party Cookies in Chrome

      July 23, 2024

      Big Brother is Watching: Apple’s Creepy New Ad Urges iPhone Users to Ditch Chrome

      July 23, 2024

      Nvidia Stock Soars to New Record at $219.44 Ahead of May 20 Earnings

      May 12, 2026

      Rocket Lab Shares Surge Past $120 Following Wave of Analyst Upgrades

      May 12, 2026

      GM Shares Decline Following 600 IT Layoffs Amid Strategic AI Workforce Transformation

      May 12, 2026

      SES Delivers €847M Q1 Performance as Intelsat Integration and Aviation Deals Fuel Expansion

      May 12, 2026
    • How To

      Batch Files: Tokens and Delimiters (FOR Loops)

      July 31, 2024

      Types of Ethernet Cabling & Electrical Low Voltage Wiring

      July 9, 2024

      What You Should Know About .JSON File Extension

      January 10, 2023

      Bkup File Extension

      November 19, 2022

      HEIC File Extension

      November 19, 2022
    • Office
      1. Excel
      2. Google Sheets
      3. View All

      How to Convert Column List to Comma Separated List in Excel

      July 24, 2024

      How to Find the Last Monday of the Month in Excel

      July 24, 2024

      Convert Bytes to MB or GB in Excel: 3 Methods!

      July 24, 2024

      How to Remove Characters from Right in Excel

      July 30, 2023

      How to Subtract in Google Sheets: Complete Guide

      July 31, 2024

      Bullet Points in Google Sheets

      January 20, 2022

      Sort by Date in Google Sheets

      January 18, 2022

      Google Sheets Timestamp

      January 17, 2022

      How to Subtract in Google Sheets: Complete Guide

      July 31, 2024

      How to Convert Column List to Comma Separated List in Excel

      July 24, 2024

      How to Find the Last Monday of the Month in Excel

      July 24, 2024

      Convert Bytes to MB or GB in Excel: 3 Methods!

      July 24, 2024
    • Answers
    • About
    • Contact
    Facebook X (Twitter)
    Computing.net
    Security

    OAuth Implementation Flaw Exposes Millions of Websites to XSS Attacks

    Researchers have discovered a widespread vulnerability that combines OAuth implementation flaws with cross-site scripting, potentially affecting millions of websites
    Oliver DaleBy Oliver DaleJuly 30, 2024
    Twitter LinkedIn Email Telegram
    Twitter LinkedIn Email Telegram

    TLDR

    • Researchers discovered an XSS attack that could impact millions of websites using OAuth for social logins
    • The vulnerability affects major services like HotJar and Business Insider, potentially exposing user data
    • The attack combines OAuth implementation flaws with cross-site scripting (XSS) vulnerabilities
    • HotJar, used by over 1 million websites, could expose sensitive user data if compromised
    • Researchers believe this issue is widespread due to the popularity of OAuth and XSS vulnerabilities

    A new security threat has emerged that could affect millions of websites worldwide. Researchers from Salt Labs, part of API security firm Salt Security, have uncovered a cross-site scripting (XSS) attack that takes advantage of how websites implement OAuth for social logins.

    OAuth is a popular standard used for features like “Login with Google” or “Login with Facebook.” It lets users sign in to websites using their accounts from other services. However, if not set up correctly, OAuth can create security risks.

    The researchers found this problem in two major online services: HotJar and Business Insider. HotJar is a tool used by over 1 million websites to track and record user activity. It works with big names like Adobe, Microsoft, T-Mobile, and Nintendo. Business Insider is a well-known news website with millions of readers around the world.

    What makes this discovery concerning is that these are big companies with strong security practices. If they can make this mistake, many other websites likely have the same issue.

    The attack works by combining two things: problems with how OAuth is set up, and an old type of web vulnerability called cross-site scripting (XSS). XSS lets attackers run malicious code in a user’s web browser.

    Here’s how the attack could work:

    • An attacker sends a victim a link that looks normal.
    • This link could come through email, text message, or social media.
    • When the victim clicks the link, it starts a login process using OAuth.
    • The attacker can then steal the login information and take over the victim’s account.

    This is dangerous because it could let attackers see and use any information in the compromised account. For a service like HotJar, this could include names, emails, addresses, and even bank details that HotJar recorded from other websites.

    Both HotJar and Business Insider fixed the problems quickly after being notified. HotJar took just three days to fix the issue. However, the researchers believe many other websites likely have the same vulnerability.

    To help address this issue, Salt Labs has released a free scanner. Website owners can use this tool to check if their OAuth implementation is vulnerable to this kind of attack.

    The discovery of this vulnerability shows that even as web security improves, new risks can emerge. It’s a reminder that website owners need to be careful when implementing new features like social logins.

    For users, this news underscores the importance of being cautious online. Even links that look legitimate could be part of an attack. It’s always a good idea to be careful about what links you click and to use strong, unique passwords for each of your online accounts.

    Share. Twitter LinkedIn Email Telegram
    Oliver Dale
    • Website
    • X (Twitter)
    • LinkedIn

    Editor-in-Chief of Computing.net and founder of Kooc Media, A UK-Based Online Media Company. Believer in Open-Source Software, Blockchain Technology & a Free and Fair Internet for all. His writing has been quoted by Nasdaq, Dow Jones, Investopedia, The New Yorker, Forbes, Techcrunch & More. Contact Oliver@blockonomi.com

    Related Posts

    Security Audit Reveals Concerns in Atari’s Blockchain Game on Base

    August 6, 2024

    SideWinder Group Targets Maritime Facilities in New Cyber Espionage Campaign

    July 30, 2024

    Hamster Kombat Players Face Growing Cybersecurity Threats

    July 25, 2024

    UK Police Arrest 17-Year-Old Suspect in MGM Resorts Cyberattack Investigation

    July 23, 2024

    Spanish Authorities Arrest Pro-Russian Hackers Targeting Ukraine’s Allies

    July 23, 2024

    Lawmakers Demand Answers: CrowdStrike CEO Called to Testify on Global Tech Outage

    July 23, 2024
    Add A Comment

    Comments are closed.

    Latest

    Nvidia Stock Soars to New Record at $219.44 Ahead of May 20 Earnings

    May 12, 2026

    Rocket Lab Shares Surge Past $120 Following Wave of Analyst Upgrades

    May 12, 2026

    GM Shares Decline Following 600 IT Layoffs Amid Strategic AI Workforce Transformation

    May 12, 2026

    SES Delivers €847M Q1 Performance as Intelsat Integration and Aviation Deals Fuel Expansion

    May 12, 2026

    Trump Dismisses Iran Peace Proposal — Oil Markets React as Hormuz Remains Restricted

    May 12, 2026
    • Facebook
    • Twitter

    Latest Reviews

    Meta Platforms Shares Tumble 8% Despite Strong Q1 Performance Amid AI Investment Surge

    April 30, 2026

    Flush.com Review: Casino & Sportsbook With 275% Welcome Bonus

    March 7, 2026

    Katsubet Review: Crypto Casino With 300% Welcome Bonus & Free Spins

    March 7, 2026

    7Bit Review: Crypto Casino With 325% Bonus & 250 FS

    March 7, 2026

    Mega Dice Review: Crypto Casino With 200% Bonus & 50 Free Spins, Legit?

    March 7, 2026


    Home / Privacy Policy / Terms & Conditions

    Computing.net © 1996 - 2026 Kooc Media Ltd. All rights reserved. Registered Company No.05695741

    Type above and press Enter to search. Press Esc to cancel.