Slack addressed a critical flaw within 24 hours from its disclosure. The issue allowed attackers to carry out automated account takeover. The bug is extremely critical not only for Slack, but also for all customers and organizations which share their private data. An attacker could have exploited this issue to create automated bots that are able to access a victims Slack session and steal sensitive data. Slack also addressed another issue, which would allow an attacker to steal XOXS tokens and gain full control over victims accounts.”]
Source: https://securityaffairs.co/wordpress/99626/hacking/slack-bugs-account-takeover.html

