Recently I was targeted by an sophisticated (Google) phishing attack(threadreaderapp.com) |
Recently I was targeted by an sophisticated (Google) phishing attack(threadreaderapp.com) |
So the meat of the issue is.. Google allows very long oauth application display names, which can look like an email body when they send notifications about that application?
In Microsoft-land this field ("display name") is limited to 120 characters.