Still not Google's fault.
TheKMAP
https://www.washingtonpost.com/technology/2020/02/14/google-maps-political-borders/
This is not new. Google will show citizens of a country whatever that country's leadership wants them to see. Usually it's related to disputed territory from wars, but has also included whiny bullshit like this.
It's in the first three words of the article. It's celebrating the anniversary, so you buy it during the anniversary period. How long do you celebrate your birthday for? If you got a birthday present to celebrate your 35th birthday six months after you turned 50, is it still a 35th birthday present?
That password reset looked to be like step four of something. So it's a business logic bypass. Still awful of course but slightly more understandable given other ways this vulnerability could have been introduced. The cool part was detecting all the steps completely blackbox because everything was in the Javascript.
There is no excuse for issuing a valid token before mfa succeeds though. That is negligent.
MY CABBAGES