Explore tweets tagged as #OAuth
@Huntio
Hunt.io
9 days
๐ŸšฉTA416 Targets Government and Diplomatic Organizations with PlugX and OAuth Phishing https://t.co/dbw8QbQ6R4 China-linked TA416 has resumed activity after a quiet period, targeting diplomatic and government organizations with updated PlugX campaigns. The group is abusing
1
10
29
@Anastasis_King
Cybersecurity by Cyberkid
11 days
Claude Bug Bounty Hunter - Claude Code skill for AI-assisted bug bounty hunting - recon, IDOR, XSS, SSRF, OAuth, GraphQL, LLM injection, and report generation https://t.co/cpAhSiQtPI
9
144
746
@charlespacker
Charles Packer
12 days
I don't get how this works. Claude OAuth + OpenClaw (OSS) = banned Claude OAuth + "personal software" using Agent SDK = OK So if I fork OpenClaw to use Agent SDK under the hood, this is OK? Or is it only OK for "personal use", and if I sell it, I am banned from allowing
@bcherny
Boris Cherny
12 days
@EricBuess Yep, working on improving clarity here to make it more explicit
51
12
422
@jonoringer
Jon Oringer
10 days
This is huge : @X released an MCP server today.. How to Connect X to your ๐Ÿฆž : **Step 1: Run the XMCP Server** git clone https://t.co/45vK6uCOKl cd xmcp cp env.example .env Edit the .env file with your X OAuth consumer key and secret. Set the callback URL to
78
213
2K
@ziwenxu_
Ziwen
12 days
Claude Banned OpenClaw OAuth? We Bypassed It. Anthropic killed 3rd-party OAuth for subs today (April 4), shoving everyone onto the expensive API. OpenClaw doesn't care. We're moving downstream. Instead of fighting the OAuth ban, we're piping Claude CLI directly into OpenClaw.
@ziwenxu_
Ziwen
12 days
Claude just banned OpenClaw and Hermes. Here's how to swap models and kill Claude MAX Oauth in under 2 mins Set this up NOW before you get locked out
126
81
865
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
6 days
HackerNotes TLDR for episode 169! https://t.co/w7HQ9TFNYo โ–บโ €OAuth 2.1 mandates PKCE, so strip code_challenge from "2.1-compliant" servers to test for downgrade vulnerabilities โ–บโ €MCP's new Client Identity Metadata Documents (CIMD) turn the authorization server into an SSRF
1
3
33
@GHCopilotCLILog
GitHub Copilot CLI Changelog
11 days
๐Ÿ—“๏ธ Weekly recap (Mar 28-Apr 4) ๐Ÿš€ 5 releases ๐Ÿ› ๏ธ 60 improvements 60 features & enhancements in this release Top features: โ€ข BYOM Model picker correctly overrides the --model flag for the session โ€ข Add device code flow (RFC 8628) for MCP OAuth in headless and CI environments โ€ข
3
4
64
@jahirsheikh8
Jahir Sheikh
4 days
As a developer, you should be able to clearly explain at least 10 of these: - Load Balancer - API Gateway - Reverse Proxy - Throttling - Rate Limiting - Idempotency - Pagination - Cache Stampede - gRPC - GraphQL - Webhooks - OAuth - JWT - Cache Invalidation - Query Optimization
47
215
1K
@agentmail
AgentMail (YC S25)
8 days
Here's how to give your Hermes agent its own email inbox. @NousResearch No SMTP/IMAP, no Google Oauth, just plug in AgentMail using MCP. See how it works:
4
4
40
@sharbel
Sharbel
13 days
Hermes Agent Full Setup Guide (Does It Actually Beat OpenClaw?): 0:00 - What is Hermes Agent 1:07 - What Makes It Different? 1:49 - Install Hermes 6:11 - The Mistake I Made 7:02 - Anthropic OAuth 8:45 - Live Demo 10:34 - Honest Verdict vs OpenClaw 12:26 - Best Workflow
45
41
499
@sytaylor
Simon Taylor
9 days
Hey @AnthropicAI you broke claude code logins with oauth too? Even though that's an option in the product? Just because I used that with openclaw before? What the hell man. Can I only API into claude code now??!
9
1
20
@0xacb
Andrรฉ Baptista
12 days
Race conditions in OAuth flows can still happen in custom implementations. Here's how to find it: During the token exchange, the server is supposed to treat an authorization code as single-use. If you race the token endpoint by sending parallel requests with the same code
7
38
258
@tech__unicorn
Delia Lazarescu
11 days
Anthropic finally killed Open Claw Oauth use for Claude Max users ๐Ÿ˜ญ hereโ€™s what you can do about it ๐Ÿ‘‡
4
1
24
@Baderasadeth
Bader Asad
4 days
@uttam_singhk We built Oauth for Agents @GetAgentID Captcha is essentially useless once there is Identity, trust, etc built into the agent infrastructure at a base level. The point of captcha is to remove bot access. Now we have to allow scoped bot access.
0
0
1
@heygurisingh
Guri Singh
8 days
While you're handing your AI agent every password you own... The top 1% already moved to @Composio. No OAuth nightmares. No credential leaks. No 3am "who authorized this" panic. Their agents are locked down in minutes. Yours are one prompt injection away from disaster. Secure
@KaranVaidya6
Karan Vaidya
8 days
Your AI agent is in bed with you. No protection. You just wanted it to work. Gmail. Allow. Calendar. Allow. Slack, Notion, GitHub. Allow. Allow. Allow. Every password, handed over. Your agent never needed a single one. They just needed @Composio Secure your agents in
33
49
576
@dani_avila7
Daniel San
5 days
Been testing Claude Managed Agents Here's my feedback: Vaults store OAuth tokens outside the sandbox, the agent never handles them directly The problem, vaults are workspace-scoped Anyone with workspace access, via API key or the Console, can reference your vaults and use
6
5
36
@The_Cyber_News
Cyber Security News
7 days
๐Ÿ›ก๏ธ Hackers Used EvilTokens, ClickFix Campaign to Attack Claude Code Users Source: https://t.co/auiLnXBqSb Two significant threat campaigns from March 2026, one abusing Microsoftโ€™s OAuth authentication flow to silently hijack enterprise accounts, and another deploying the AMOS
1
20
50
@hmartapp
๐’ฝ๐“‚
1 day
์Œ ๊ฒฐ๊ตญ ์ดํ›„์— ์“ธ AI ๊ตฌ๋…์€ Claude Code ๋ณด๋‹ค Codex ๋ฅผ ํƒํ•  ๊ฒƒ ๊ฐ™๋‹ค... ์—์ด์ „ํŠธ ์ž์ฒด๋ฅผ ๋ณ„๋„ ํ”„๋กœ๊ทธ๋žจ์œผ๋กœ ์ง์ ‘ ๋งŒ๋“ค ๋•Œ์— โ€œAPIํ‚คโ€ ๊ฐ€ ์•„๋‹ˆ๋ผ โ€œOAUTH APIํ‚คโ€ ๋ฅผ ์“ธ ์ˆ˜ ์žˆ์–ด์•ผ.. ๋‚ด ๊ตฌ๋…์„ ๊ทธ๋Œ€๋กœ ์“ธ ์ˆ˜ ์žˆ๋‹ค๋ฉด APIํ‚ค๋ณด๋‹ค 20๋ฐฐ๋Š” ์ €๋ ดํ•˜๊ฒŒ ์ฒ˜๋ฆฌํ•  ์ˆ˜ ์žˆ๋Š”๋ฐ ์ด๊ฑธ ๋” ๋น„์‹ผ APIํ‚ค๋กœ ๋‹ค์‹œ ์งœ๋Š”๊ฑด ์ข€..
2
0
11
@DataChaz
Charly Wargnier
8 days
Cleanest approach Iโ€™ve seen for agent auth: OAuth + per-action permissions! Composio really nailed this ๐Ÿ‘๐Ÿ‘๐Ÿ‘
@KaranVaidya6
Karan Vaidya
8 days
Your AI agent is in bed with you. No protection. You just wanted it to work. Gmail. Allow. Calendar. Allow. Slack, Notion, GitHub. Allow. Allow. Allow. Every password, handed over. Your agent never needed a single one. They just needed @Composio Secure your agents in
6
11
34