Account Takeover Attack on X via OAuth Impersonation

2 grinich 1 7/5/2025, 5:15:22 PM twitter.com ↗

Comments (1)

sherdil2022 · 2h ago
This is scary.

The url says www.calender.google.com - typo - calender instead of calendar - but still google.com.

If the TLD is legit, how can anyone figure out this is a suspicious app?

Even a legitimate app asking for full-access to an account shouldn’t be approved by X.