Nicholas Whittaker 9/23/2021

A suspicious email from Cloudflare

Read Original

The author details receiving a suspicious email about a Cloudflare account created with their address. Their investigation reveals a security flaw where unverified accounts can provision API tokens that persist even after a password reset, allowing attackers to maintain access. The article explains the potential account takeover risk and the steps taken to secure the account.

A suspicious email from Cloudflare

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week