IBM's X-Force Application Security Research Team devised a logical attack that allows a malicious user to intrude into user accounts on a relying website (that is, a website that relies on authentication assertions passed to it by the identity provider) by abusing the social login mechanism. For more: http://securityintelligence.com/spoofedme-social-login-attack-discovered-by-ibm-x-force-researchers/
IBM's X-Force Application Security Research Team devised a logical attack that allows a malicious user to intrude into user accounts on a relying website (that is, a website that relies on authentication assertions passed to it by the identity provider) by abusing the social login mechanism. For more: http://securityintelligence.com/spoofedme-social-login-attack-discovered-by-ibm-x-force-researchers/