| |
Someone used my open source project to phish 14,000 people
# Summary An attacker exploited the open-source project Kaneo's cloud signup form to create 949 fake accounts and send 14,520 phishing emails to strangers using the developer's verified Resend email domain. The attack required no technical exploitation—the attacker simply abused the unprotected signup process, highlighting how open-source projects with cloud versions face unique security risks when convenience features lack basic safeguards like CAPTCHAs and rate limits.
Read Full Article →
← More Tech news