Post #1253022
2026-04-03 19:22 UTC
@Viss @dangoodin years ago there was a vulnerability in which credentials (OAuth tokens IIRC) were exposed in plaintext in every API message sent from a Slack API to another SaaS API
I've seen similar patterns in other situations, and I see confused deputy issues regularly (and I imagine increasingly frequently with agentic attack surfaces)
Seems like a ripe landscape to take advantage of privesc
"OpenClaw" is a good name because I imagine it scuttling sideways to move laterally between allll the things
(with a *cough* paring knife, of course)
Replies (1)
-
@Viss@mastodon.social 2026-04-03 21:50
@saraislet @dangoodin you mess with crabbo, you get a stabbo!