How to defeat second-factor authentication, OAuth flows, and clickjacking that ends in account takeover. The line between Medium and Critical findings.