FT#OV}XY#$A:_/ATT*R/G=:O0D]%Q
SYSTEM PROCESSING...
FT#OV}XY#$A:_/ATT*R/G=:O0D]%Q
SYSTEM PROCESSING...
Posted: 2025-04-16 11:41:42 UTC

This article contains some claims that remain unverified. While much of the content may be accurate, exercise care when relying on this information.
This article contains some claims that remain unverified. While much of the content may be accurate, exercise care when relying on this information.
Status
Last Updated
2025-04-16 11:42:41 UTC
Verified By
Rollup News
The author describes a sophisticated phishing attack that exploits vulnerabilities in Google's infrastructure, specifically through Google Sites and a clever use of OAuth applications to send valid, signed emails. Google has declined to fix the reported vulnerabilities, considering them 'Working as Intended'.
Phishing attack exploits Google Sites vulnerability
Valid, signed emails used for phishing
Google's refusal to fix the vulnerabilities
OAuth application abuse
Google's refusal to acknowledge the security vulnerability
Difficulty in reporting abuse from the Sites interface
Users assuming legitimacy due to the google.com domain