Learn
active
One-Click-to-Leak: Trust Defects in MNO-Based SSO Websites
- Engineer — Learn: Academic research exposing trust hijacking and credential leakage flaws in carrier-based SSO; the finding that 69.4% of MSSO sites expose developer credentials is a useful design caution for any team integrating telecom-backed identity flows, though MSSO is rare in typical US cloud stacks.
- SOC/IR — Learn: The One-Click-to-Leak attack class (phone number exfiltration via single page visit) is a novel auth-layer technique worth filing for threat modeling, but the paper provides no IOCs, ATT&CK mappings, or detection rules to act on today.
- Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.