On July 20, SlowMist Yu Xian posted on social media that there have been a large number of phishing email attacks targeting X platform users recently. These emails, with the subject "New login to X From XXX", can bypass the Gmail spam filtering system. Attackers induce users to click on the "Change your password" or "Review the apps" links by forging abnormal account login notifications, actually directing users to the official X third-party application authorization page. Once the user authorizes, the attacker will obtain the permission to publish and forward tweets, and can control the user's account to publish content without their knowledge. Users must be vigilant, carefully handle any email notifications claiming abnormal login to X accounts, and avoid clicking on the links in the email and authorizing applications at will. [TechFlow TechFlow]