#OAuth
37 stories taggedOAuth.

A flaw in the official MCP Python SDK let hostile servers walk off with OAuth logins
Applications built on Anthropic's Model Context Protocol client library could be tricked into sending real service credentials to an attacker-controlled endpoint. The fix is in version 1.30.0.

F5's BIG-IP Flaw Was Already Being Exploited Before a Patch Existed
A critical security hole in widely used network hardware is under active attack. Federal agencies have three days to patch. Here's what the flaw does and who is at risk.

EvilTokens: the phishing kit that turned a smart-TV login trick into a mass account raid
Microsoft says a subscription phishing service broke into more than 12,000 mailboxes by abusing the sign-in flow built for printers and conference room screens.

GhostCode Phishing Kit Turns Microsoft's Own Login Flow Against You
A new tool called GhostCode abuses a legitimate Microsoft sign-in mechanism to steal account access, register attacker-controlled devices, and survive password resets, all in under 90 seconds.

The Google Workspace apps you forgot about are still reading your email
Third-party integrations left connected to Workspace tenants keep their access for years, and attackers are quietly walking through the door they left open.

Malicious Twitch Extension Siphoned Login Tokens From 31,000 Viewers
A browser add-on marketed as a Twitch viewer tool quietly forwarded OAuth tokens to servers linked to a Russian bot-for-hire service.

ChatGPT is learning to write like you, by reading your Gmail and Slack
OpenAI is testing a 'Writing Style' feature that studies your own messages and documents so the chatbot can mimic your voice. The privacy trade is real.

The Fake IT Call and the Click That Opens the Door
Attackers are skipping the smash-and-grab, choosing polite phone calls, spoofed login pages and poisoned software guides to walk in through the front door.

The Week in Identity: Router Backdoors, Off-Task AI Agents, and Login Kits for Sale
A weekly roundup of the dull-sounding defaults, forgotten bugs, and helpful chatbots that quietly handed attackers the keys this week.

McKesson Confirms Break-In After Hackers Claim 284 Million Patient Records Stolen
The US pharmaceutical distribution giant says intruders reached third-party apps holding limited data. The ShinyHunters gang claims a haul far larger than McKesson admits.

When Your AI Assistant Goes Rogue: What To Do in the First 24 Hours
An hour-by-hour guide for what actually happens when an AI agent starts doing things nobody asked it to do, drawn from real incidents and written for everyone who might be caught in the fallout.

When Google Workspace gets breached, the door is usually already open
Most Workspace break-ins start with a tricked employee or a forgotten app connection, not a clever hack. Here is what actually happens in the first hours, and what stops the damage.

Snowflake kills passwords for service accounts. The cleanup starts now.
The cloud data giant is retiring password logins for machine accounts. Working out what those accounts actually do is the real headache.

OAuth Tokens Are Quietly Becoming the Skeleton Key to Google Workspace
Phishing gets the headlines, but stolen app tokens can open Gmail and Drive without ever tripping a login alert.

Four Million Fake App IDs, One Blind Spot: How Hackers Are Slipping Past Microsoft Login Defences
Two criminal campaigns sent over four million spoofed application identities at Microsoft's sign-in system and barely triggered an alert. Here is what happened, who is at risk, and what security teams can do.