Security
RIPE NCC SSO Cookie Scope Exposed Session Tokens to 1,000-Plus Third Parties
Security researcher Sasha Romijn disclosed that RIPE NCC's SSO session cookie was scoped to *.ripe.net, exposing it to more than 1,000 third-party-controlled hosts. Combined with permissive CAA records, any rogue operator on that domain could have stolen tokens giving full read-write access to routing infrastructure for Europe, the Middle East, and Central Asia.