OAuth redirection is being repurposed as a phishing delivery path. Trusted authentication flows are weaponized to move users from legitimate sign‑in pages to attacker‑controlled infrastructure.
Student reporters at Michigan State explain how public records helped them uncover misconduct, investigations and hidden decisions.