A publicly accessible Google Group under the openssl.org domain let a researcher receive verification messages and authenticate to a community portal as an official OpenSSL.org email identity. OpenSSL was notified and promptly corrected the group configuration. Broader testing using Go-based reconnaissance tooling identified more than 150 publicly readable or writable Google Groups, though membership, moderation, spam filtering, and other controls limited exploitability for many of them.
The issue revives the Ticket Trick technique, in which attackers abuse helpdesk, mailing-list, or issue-tracker email workflows to intercept password-reset links, magic links, or one-time codes issued to a trusted corporate-domain address. Earlier research found the technique could expose internal collaboration platforms, support tickets, social-media accounts, and privileged services through flawed email verification and SSO integrations involving platforms such as GitLab, Zendesk, and Kayako. Organizations should eliminate public or unnecessary external access to domain-associated groups and avoid treating email OTPs or magic links as proof of organizational identity; federated authentication using OIDC or SAML provides stronger assurance.

See affected versions and whether adversaries are exploiting it.
9 events from the most recent confirmed update back to the earliest known activity.
The researcher reported the OpenSSL.org Google Group misconfiguration, and the OpenSSL team promptly corrected the configuration.
A researcher found that a misconfigured OpenSSL.org Google Group allowed authentication to a mail-OTP community portal as an official openssl.org email address.
Inti De Ceukelaire published research describing Ticket Trick, an attack method that abused helpdesk and issue-tracker email workflows to capture verification or password-reset messages and access organizational accounts.
De Ceukelaire reported joining eight unauthorized Slack channels used by 332 employees at a large payment processing company and receiving a $5,000 bounty for the finding.
After being informed of the broader helpdesk-abuse issue, Slack changed its no-reply email address to include a random token, mitigating a portion of the Ticket Trick workflow.
Kayako and Zendesk fixed the reported bypass issues; De Ceukelaire said the vendors awarded bug bounties of $1,000 and $750 respectively.
De Ceukelaire reported email-verification bypass flaws in common Kayako and Zendesk configurations through responsible-disclosure channels.
Following the report, GitLab made its Slack workspace invite-only, took additional mitigation steps, and updated documentation warning about risks from company-domain email integrations.
Inti De Ceukelaire used a GitLab issue-creation email address to receive a Slack verification email and join GitLab's internal Slack team, demonstrating the Ticket Trick technique.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.