Security News The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed TheHackerNews Daniel Bender 05 May 2026 OAuth tokens without expiry enable breaches like Drift attack on 700+ firms, bypassing MFA and exposing sensitive data.