Tag

#OAuth

37 stories taggedOAuth.

Illustration: a dimly lit developer workstation at night
Identity & Access

A flaw in the official MCP Python SDK let hostile servers walk off with OAuth logins

Applications built on Anthropic's Model Context Protocol client library could be tricked into sending real service credentials to an attacker-controlled endpoint. The fix is in version 1.30.0.

4 min read
Illustration: a rack-mounted enterprise network appliance with blinking amber and red status lights in a darkened server room
Vulnerabilities

F5's BIG-IP Flaw Was Already Being Exploited Before a Patch Existed

A critical security hole in widely used network hardware is under active attack. Federal agencies have three days to patch. Here's what the flaw does and who is at risk.

3 min read
Illustration: a dimly lit modern conference room with a large wall-mounted video conferencing screen displaying an abstract
Identity & Access

EvilTokens: the phishing kit that turned a smart-TV login trick into a mass account raid

Microsoft says a subscription phishing service broke into more than 12,000 mailboxes by abusing the sign-in flow built for printers and conference room screens.

4 min read
A glowing blue padlock made of translucent code fragments slowly dissolving into streams of light against a dark server room background, with rows of blinking r
Identity & Access

GhostCode Phishing Kit Turns Microsoft's Own Login Flow Against You

A new tool called GhostCode abuses a legitimate Microsoft sign-in mechanism to steal account access, register attacker-controlled devices, and survive password resets, all in under 90 seconds.

4 min read
A Google Workspace administration console showing connected third-party applications with persistent access permissions, highlighting outdated integrations that
Cloud Security

The Google Workspace apps you forgot about are still reading your email

Third-party integrations left connected to Workspace tenants keep their access for years, and attackers are quietly walking through the door they left open.

3 min read
A streaming platform interface on a monitor with a browser extension icon highlighted in red, data packets flowing digitally across the screen toward an obscure
Threat Intelligence

Malicious Twitch Extension Siphoned Login Tokens From 31,000 Viewers

A browser add-on marketed as a Twitch viewer tool quietly forwarded OAuth tokens to servers linked to a Russian bot-for-hire service.

4 min read
A computer screen showing ChatGPT interface with Gmail and Slack windows open in the background, document text highlighted, writing samples displayed, conveying
AI Security

ChatGPT is learning to write like you, by reading your Gmail and Slack

OpenAI is testing a 'Writing Style' feature that studies your own messages and documents so the chatbot can mimic your voice. The privacy trade is real.

4 min read
An office worker at a desk during a phone call, a fake login page displayed on their monitor screen, with a hand reaching toward the keyboard about to enter cre
Threat Intelligence

The Fake IT Call and the Click That Opens the Door

Attackers are skipping the smash-and-grab, choosing polite phone calls, spoofed login pages and poisoned software guides to walk in through the front door.

4 min read
Close-up of a router's ethernet ports glowing with activity lights, a single red warning indicator blinking among the green, dust settling on the device's venti
Threat Intelligence

The Week in Identity: Router Backdoors, Off-Task AI Agents, and Login Kits for Sale

A weekly roundup of the dull-sounding defaults, forgotten bugs, and helpful chatbots that quietly handed attackers the keys this week.

4 min read
A sprawling pharmaceutical warehouse or distribution center at night, with security lights illuminating rows of shelving units and inventory, a single door or a
Breaches

McKesson Confirms Break-In After Hackers Claim 284 Million Patient Records Stolen

The US pharmaceutical distribution giant says intruders reached third-party apps holding limited data. The ShinyHunters gang claims a haul far larger than McKesson admits.

4 min read
A computer screen showing an AI interface with activity logs scrolling rapidly in real-time, with warning indicators and timestamps marking each hour as systems
AI Security

When Your AI Assistant Goes Rogue: What To Do in the First 24 Hours

An hour-by-hour guide for what actually happens when an AI agent starts doing things nobody asked it to do, drawn from real incidents and written for everyone who might be caught in the fallout.

5 min read
An office worker at a desk, face obscured, staring at a computer screen showing security alerts and suspicious login notifications during business hours
Identity & Access

When Google Workspace gets breached, the door is usually already open

Most Workspace break-ins start with a tricked employee or a forgotten app connection, not a clever hack. Here is what actually happens in the first hours, and what stops the damage.

3 min read
A cloud platform dashboard with service account management interface, showing a complex web of machine-to-machine authentications, credentials being deprecated,
Identity & Access

Snowflake kills passwords for service accounts. The cleanup starts now.

The cloud data giant is retiring password logins for machine accounts. Working out what those accounts actually do is the real headache.

4 min read
Gmail and Google Drive interface open on a computer screen with access granted through stolen OAuth tokens, showing unauthorized file access and email reading w
Cloud Security

OAuth Tokens Are Quietly Becoming the Skeleton Key to Google Workspace

Phishing gets the headlines, but stolen app tokens can open Gmail and Drive without ever tripping a login alert.

4 min read
A security operations center where analysts are tracking millions of spoofed login attempts on large dashboard displays, threat intelligence feeds scrolling acr
Identity & Access

Four Million Fake App IDs, One Blind Spot: How Hackers Are Slipping Past Microsoft Login Defences

Two criminal campaigns sent over four million spoofed application identities at Microsoft's sign-in system and barely triggered an alert. Here is what happened, who is at risk, and what security teams can do.

5 min read
© 2026 Threat Vectr