{"id":3653,"date":"2018-06-19T20:11:48","date_gmt":"2018-06-19T20:11:48","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/"},"modified":"2018-06-19T20:11:48","modified_gmt":"2018-06-19T20:11:48","slug":"yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/","title":{"rendered":"Yubico snatched my login token vulnerability to claim a $5k Google bug bounty, says bloke"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2017\/02\/16\/yubikey_card.jpg?x=1200&amp;y=794\" class=\"ff-og-image-inserted\"\/><\/div>\n<p>Yubico has apologized to a security vulnerability researcher who had complained the dongle peddler lifted his work to nab a $5,000 Google bug bounty.<\/p>\n<p>Over the weekend, Marcus Vervier <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/pwnaccelerator.github.io\/2018\/webusb-yubico-disclosure.html\">described<\/a> how he and fellow infosec bod Michele Orru discovered flaws that could be exploited by miscreants to steal people&#8217;s two-factor authentication codes.<\/p>\n<p>Basically, you can register a USB YubiKey from Yubico with, say, your Facebook.com account so that when logging into the social network, you type in your password, plug in your YubiKey and press a button on it, and successfully log in. If you, or a hacker, doesn&#8217;t have the key, they can&#8217;t get into your account.<\/p>\n<p>The YubiKey only hands over a two-factor authentication token if it is satisfied the browser really is visiting facebook.com, using the <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/fidoalliance.org\/specifications\/overview\/\">U2F<\/a> protocol to verify the identity of the requesting site.<\/p>\n<p>Enter <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/wicg.github.io\/webusb\/\">WebUSB<\/a>, which allows websites to access USB devices. Vervier and Orru found they could craft webpages that masquerade as real sites, such as facebook.com, and could still read from YubiKey tokens. Such a malicious phishing site could therefore trick victims into handing over their Facebook username, password, and two-factor code, and log in as them to cause havoc.<\/p>\n<p>The pair presented their research on the subject earlier this year at the OffensiveCon security conference \u2013 as seen in the video below. Vervier said that after their work was publicized, Yubico got in touch asking for more information.<\/p>\n<p><a href=\"https:\/\/www.youtube.com\/watch?v=pUa6nWWTO4o\" data-media=\"x-videoplayer\">Youtube Video<\/a><\/p>\n<p>Fast forward to last week, when Yubico <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/www.yubico.com\/2018\/06\/webusb-and-responsible-disclosure\/\">disclosed its own findings<\/a> on exploiting WebUSB to steal codes, including the revelation that the company had reported the issue to Google&#8217;s Chromium browser project \u2013 the core software of Google Chrome \u2013 and received a $5,000 bounty in return.<\/p>\n<p>Yubico reported the security weakness to Google because Android and Chromium were particularly vulnerable, and Google shored up its software.<\/p>\n<p>Here is where the problem arises. Vervier claims he and Orru also reported the issue to Google, but did not hear back. It appears Yubico beat them to it, tipping off Google after speaking to the duo but before the pair could formally disclose the vulnerability to the web giant.<\/p>\n<p>Yubico claimed its disclosure expanded on their original work but did not specifically credit either Vervier or Orru.<\/p>\n<p>&#8220;Yubico had internally replicated our work, contacted us to gather information about what we have not released so far, asked us for help to create a PoC [proof of concept exploit], but did not tell us anything about their intentions?&#8221; a clearly irritated Vervier wrote.<\/p>\n<p>&#8220;Then went to Google, two days later submitting a comprehensive analysis of the research, claiming to have new original content and gaining a 5,000 USD bounty for this.&#8221;<\/p>\n<p>For what it&#8217;s worth, the bounty payout was donated by Yubico to Girls Who Code, a decision Vervier supports. It&#8217;s not about the money, but rather the lack of credit he says he and Orru were not given for their work by a major security vendor.<\/p>\n<p>&#8220;I always believed in working with vendors to get issues fixed, but things like this makes you wonder why people hoarding exploits, doing full disclosure, or selling them have an apparently easy and prosperous life,&#8221; Vervier said.<\/p>\n<p>&#8220;On a professional level I never had any problems with work and research when being contracted to do security audits, expectations and responsibilities are clear. But as a private researcher it seems like being nice just means trouble.&#8221;<\/p>\n<p>Yubico, when contacted by <em>The Register<\/em>, admitted it messed up by not crediting the duo for their contributions. The Yubico write-up on the issue has since been updated to credit the researchers, and Yubico said it has apologized to both.<\/p>\n<p>&#8220;Markus and Michele\u2019s research provided a critical foundation, and we made a mistake by not clearly acknowledging them for their original research in our initial security advisory,&#8221; Yubico said.<\/p>\n<p>&#8220;We learned only on June 13, after we published our advisory, that Markus and Michele also discovered and reported HID issues to Google. We understand that better communication after the issue was fixed would have ensured that all parties were in sync, and will use this as an opportunity for improvement.&#8221; \u00ae<\/p>\n<p class=\"wptl btm\"><span>Sponsored:<\/span> <a href=\"https:\/\/go.theregister.co.uk\/tl\/1759\/shttp:\/\/www.mcubed.london\/\">Minds Mastering Machines &#8211; Call for papers now open<\/a><\/p>\n<p>READ MORE <a href=\"http:\/\/go.theregister.com\/feed\/www.theregister.co.uk\/2018\/06\/18\/yubico_webusb_google_bounty\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>USB gizmo biz apologies amid infosec drama Yubico has apologized to a security vulnerability researcher who had complained the dongle peddler lifted his work to nab a $5,000 Google bug bounty.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":3654,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-3653","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.9 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Yubico snatched my login token vulnerability to claim a $5k Google bug bounty, says bloke 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Yubico snatched my login token vulnerability to claim a $5k Google bug bounty, says bloke 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2018-06-19T20:11:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"794\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Yubico snatched my login token vulnerability to claim a $5k Google bug bounty, says bloke\",\"datePublished\":\"2018-06-19T20:11:48+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\\\/\"},\"wordCount\":720,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/06\\\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\\\/\",\"name\":\"Yubico snatched my login token vulnerability to claim a $5k Google bug bounty, says bloke 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/06\\\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke.jpg\",\"datePublished\":\"2018-06-19T20:11:48+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/06\\\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2018\\\/06\\\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke.jpg\",\"width\":1200,\"height\":794},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Yubico snatched my login token vulnerability to claim a $5k Google bug bounty, says bloke\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Yubico snatched my login token vulnerability to claim a $5k Google bug bounty, says bloke 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/","og_locale":"en_US","og_type":"article","og_title":"Yubico snatched my login token vulnerability to claim a $5k Google bug bounty, says bloke 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2018-06-19T20:11:48+00:00","og_image":[{"width":1200,"height":794,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Yubico snatched my login token vulnerability to claim a $5k Google bug bounty, says bloke","datePublished":"2018-06-19T20:11:48+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/"},"wordCount":720,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/","url":"https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/","name":"Yubico snatched my login token vulnerability to claim a $5k Google bug bounty, says bloke 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke.jpg","datePublished":"2018-06-19T20:11:48+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2018\/06\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke.jpg","width":1200,"height":794},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/yubico-snatched-my-login-token-vulnerability-to-claim-a-5k-google-bug-bounty-says-bloke\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Yubico snatched my login token vulnerability to claim a $5k Google bug bounty, says bloke"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/3653","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=3653"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/3653\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/3654"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=3653"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=3653"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=3653"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}