Tech News
← Home  ·  All topics

Email Security

2 GoKawiil briefs on this topic

Aikido Security finds GitLab issue-creation email addresses can grant account-level access

Aikido Security published research showing that GitLab's per-user incoming email address, meant to let users create project issues via email, contains a non-expiring token that functions as an authentication and authorization credential. Because GitLab treats any message sent to that address as coming from its owner, exposure of the address alone can let an attacker create issues, submit merge requests, or send patch files across an organization's public and private projects without needing account credentials.

New phishing scams bypass classic warning signs, security researchers warn

Security researchers are flagging a fresh wave of email scams that no longer follow the old telltale patterns like poor grammar or suspicious links. These updated schemes are polished, convincing, and designed to slip past users who rely on outdated advice from corporate IT departments.