Since August, there have been numerous reports from users of X (formerly Twitter) receiving unsolicited password reset emails, with a significant spike observed on September 1st. These emails, although sent from X's legitimate system, were not initiated by the users themselves. It appears that attackers are using publicly available usernames to repeatedly manipulate the 'Forgot Password' form on X. As a result, legitimate emails are being sent to the registered addresses...