Tag

#OAuth

39 stories taggedOAuth.

A dark server room interior shot from floor level looking up at towering rack equipment, status LEDs casting blue and amber light across cables and metal chassi
Cloud Security

OAuth Tokens Are Quietly Becoming the Skeleton Key to Google Workspace

Phishing gets the headlines, but stolen app tokens can open Gmail and Drive without ever tripping a login alert.

4 min read
A digital illustration showing a hacker targeting Microsoft 365 through OAuth
Identity & Access

Four Million Fake App IDs, One Blind Spot: How Hackers Are Slipping Past Microsoft Login Defences

Two criminal campaigns sent over four million spoofed application identities at Microsoft's sign-in system and barely triggered an alert. Here is what happened, who is at risk, and what security teams can do about it.

5 min read
Full-frame edge-to-edge overhead photoreal shot of a generic black Android smartphone face-up on a matte gray desk, screen glowing pale blue with abstract geome
Identity & Access

Device Code Phishing: The Login Trick That Blew Up in 2026

A login flow built for smart TVs is now one of the fastest-growing routes into corporate accounts, and identity teams are struggling to keep up.

4 min read
A weathered combination padlock resting on a cracked concrete surface, surrounded by a tangled web of thin copper wires spreading outward in all directions, pho
Identity & Access

AI agents with too many keys: why permissions are the new identity problem

As companies rush to deploy AI assistants that act on their behalf, security researchers warn the real danger is not the AI itself but the sweeping access rights it inherits.

4 min read
Extreme close-up of a server rack's blinking status lights in a darkened data centre, rows of ethernet cables in cool blue and amber tones, shallow depth of fie
Identity & Access

Changing Your Password No Longer Kicks Hackers Out

A growing wave of attacks steals not passwords but the digital passes that keep you logged in, meaning a password reset leaves the intruder sitting comfortably inside your account.

4 min read
Extreme close-up of a glowing computer motherboard at night, thousands of tiny amber and red lights pulsing across circuit traces, shallow depth of field, dark
Identity & Access

The AI helpers your staff installed without telling IT

Autonomous AI agents are quietly attaching themselves to company accounts, often with wide permissions and no oversight. Here is what that means and how to get a grip on it.

4 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Cloud Security

The Hackers Got Hacked: Inside the Klue Breach and What It Means for Every Business Using Cloud Software

A forgotten service account let criminals walk into a competitive-intelligence platform. Then a second criminal group stole the stolen data. The whole chain is a masterclass in how cloud software trust goes wrong.

4 min read
A digital representation of cybersecurity shields and email icons, illustrating the concept of email security
Cloud Security

Your Company Uses Hundreds of Cloud Apps. Security Teams Can See Inside Almost None of Them.

Three real breaches show how misconfigured software-as-a-service tools leak customer records, private messages, and source code, all without anyone breaking down a single door.

4 min read
Photoreal editorial image, 16:9 full frame edge to edge
Vulnerabilities

RabbitMQ Bugs Could Have Handed Attackers the Keys to Corporate Messaging

Two access control flaws in the widely used RabbitMQ broker exposed OAuth secrets and let one tenant peek at another's data.

3 min read
Full frame photoreal editorial shot of a dimly lit corporate server room with soft blue rack lights, a single glowing cloud-shaped indicator on a monitoring scr
Identity & Access

Hackers Are Faking OAuth App IDs to Quietly Test Stolen Microsoft Logins

A new trick lets attackers check stolen Microsoft Entra ID passwords without triggering a single sign-in alert.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a sleek dark workstation with several glowing monitors showing abstract code and login prompts, a fain
Identity & Access

Forg365 Sells Ready-Made Microsoft 365 Hijacking Kits on Telegram for $400 a Month

A new phishing service hands criminals automated tools to break into Microsoft 365 accounts and stay there, even after a victim changes their password.

3 min read
Photoreal editorial shot of a modern office at dusk, glass doors held slightly open with a keycard dangling from a lanyard on the handle, soft blue interior lig
Identity & Access

How ShinyHunters walked into Salesforce accounts without breaking anything

Microsoft says a year of data theft from Salesforce tenants leaned on trusted app connections, not a platform bug.

4 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Vulnerabilities

A Hidden Door in RabbitMQ Left Company Systems Wide Open for Two Years

A flaw in the popular messaging software handed anyone on the network a master key to company data. Patches are out. Use them now.

3 min read
Photoreal news-editorial 16:9 photograph of a dense tangle of illuminated fibre-optic cables running through a dark server room, cool blue and amber light catch
Vulnerabilities

Two Security Flaws in RabbitMQ Could Let Attackers Steal Login Secrets and Take Over Corporate Messaging Systems

A widely used software tool that moves data between business applications has patched two vulnerabilities, one of which could hand criminals full control over the system without a password.

3 min read
Full-frame edge-to-edge photoreal news-editorial shot of a dim server room aisle at night, rows of dark server racks with faint green and amber status lights re
Threat Intelligence

Old, Silent GitHub Accounts Are Being Used to Quietly Map Companies

Datadog Security Labs says several overlapping scraping campaigns are cataloguing corporate GitHub organisations using dormant 'ghost' accounts and stolen tokens.

3 min read
© 2026 Threat Vectr