CuraSec

Learn active

One-Click-to-Leak: Trust Defects in MNO-Based SSO Websites

2026-09-14 18:03 UTC · arXiv cs.CR · read the source ↗ #single-sign-on#identity#authentication
  • Engineer — Learn: Academic research exposing trust hijacking and credential leakage flaws in carrier-based SSO; the finding that 69.4% of MSSO sites expose developer credentials is a useful design caution for any team integrating telecom-backed identity flows, though MSSO is rare in typical US cloud stacks.
  • SOC/IR — Learn: The One-Click-to-Leak attack class (phone number exfiltration via single page visit) is a novel auth-layer technique worth filing for threat modeling, but the paper provides no IOCs, ATT&CK mappings, or detection rules to act on today.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.