#AccessTokens
Exciting news! @GitHub now offers default push protection for all public repositories to safeguard against accidental leaks of secrets like access tokens and API keys. #GitHub #Potatosecurity #CodeSecurity #APIKeys #AccessTokens
March 1, 2024 at 5:15 AM
It seems that ConditionalAcces in #EntraID has become useless for Apps requiring only minimum Graph scopes when authenticating.

When requesting Accesstokens with OAuth for an App, CA-Policies are not applied (anymore). As described:
learn.microsoft.com/en-us/entra/...
Cloud apps, actions, and authentication context in Conditional Access policy - Microsoft Entra ID
What are cloud apps, actions, and authentication context in a Microsoft Entra Conditional Access policy
learn.microsoft.com
December 18, 2024 at 10:29 AM
building a new api ... and I'm stuck on which approach use AccessTokens vs HmacSha256 vs JWT
June 2, 2025 at 12:49 PM
OpenAI Codex Bug Leads to GitHub Token Breach #AccessTokens #CyberSecurity #Datahack
OpenAI Codex Bug Leads to GitHub Token Breach
  In March 2026, researchers from BeyondTrust showed that a tailored GitHub branch name was enough to steal Codex’s OAuth token in cleartext. Tech giant OpenAI termed it as “Critical P1”. Soon after, Anthropic’s Claude Code source code leaked into the public npm registry, and Adversa’s Claude Code mutely ignored its own deny protocols once a prompt (command) exceeded over 50 subcommands. Malicious codes in AI These codes were not isolated vulnerabilities. They were new in a nine-month campaign: six research teams revealed exploits against Copilot, Vertex AI, Codex, Claude Code. Every exploit followed the same strategy. An AI agent kept a credential, performed an action, and verified to a production system without any human session supporting the request. The attack surface was first showcased at Balck Hat USA 2025, where experts hacked ChatGPT, Microsoft Copilot Studio, Gemini, Cursor and many more, on stage, with zero clicks. After nine, threat actors breached those same credentials. How a branch name in Codex compromised GitHub Researchers at BeyondTrust found Codex cloned repositories using a GitHub OAuth token attached in the git remote URL. While cloning, the branch name label allowed malicious data into the setup script. A backtick subshell and a semicolon changed the branch name into an extraction payload. About the bug The vulnerability affects the ChatGPT website, Codex CLI, Codex SDK, and the Codex IDE Extension. All reported issues have since been fixed in collaboration with OpenAI's security team. This vulnerability allows an attacker to inject arbitrary commands through the GitHub branch name parameter, potentially leading to the theft of a victim's GitHub User Access Token—the same token Codex uses to authenticate with GitHub—through automated techniques. A victim's GitHub User Access Token, which Codex needs to authenticate with GitHub, may be stolen as a result. Vulnerability impact This vulnerability can scale to compromise numerous people interacting with a shared environment or GitHub repository using automated ways. The Codex CLI, Codex SDK, Codex IDE Extension, and the ChatGPT website are all impacted by the vulnerability. Since then, every issue that was reported has been fixed in collaboration with OpenAI's security team. “OpenAI Codex is a cloud-based coding agent, accessible through ChatGPT. It allows users to point the tool toward a codebase and submit tasks through a prompt. Codex then spins up a managed container instance to execute these tasks—such as generating code, answering questions about a codebase, creating pull requests, and performing code reviews against the selected repository,” said Beyond Trust.
dlvr.it
May 12, 2026 at 3:19 PM
Blockchain-based contest for Trump National dinner running through May 12 promising top 220 $TRUMP holders dinner with president,@CNBC #BlockchainContest #AccessTokens #CryptoEvents
May 11, 2025 at 6:45 AM
Exciting news! @GitHub now offers default push protection for all public repositories to safeguard against accidental leaks of secrets like access tokens and API keys. #GitHub #Cybersecurity #CodeSecurity #APIKeys #AccessTokens
March 1, 2024 at 4:50 AM