Tag

#OAuth

37 stories taggedOAuth · page 2 of 3.

A smart TV setup with a device code login screen displayed, corporate office network architecture visible in the background, breach pathways illustrated through
Identity & Access

Device Code Phishing: The Login Trick That Blew Up in 2026

A login flow built for smart TVs is now one of the fastest-growing routes into corporate accounts, and identity teams are struggling to keep up.

4 min read
An AI agent with multiple oversized keys floating around it, each granting access to different company systems, with security researchers observing from the sid
Identity & Access

AI agents with too many keys: why permissions are the new identity problem

As companies rush to deploy AI assistants that act on their behalf, security researchers warn the real danger is not the AI itself but the sweeping access rights it inherits.

4 min read
A laptop screen showing an attacker's session still active in an email inbox even after a user has reset their password, demonstrating a persistent session toke
Identity & Access

Changing Your Password No Longer Kicks Hackers Out

A growing wave of attacks steals not passwords but the digital passes that keep you logged in, meaning a password reset leaves the intruder sitting comfortably inside your account.

4 min read
Close-up of a laptop keyboard with a glowing AI icon overlay appearing on the screen, surrounded by permission dialog boxes and access notifications spreading a
Identity & Access

The AI helpers your staff installed without telling IT

Autonomous AI agents are quietly attaching themselves to company accounts, often with wide permissions and no oversight. Here is what that means and how to get a grip on it.

4 min read
A network architecture diagram showing a cloud platform with a forgotten service account highlighted, then a second breach arrow showing stolen data being stole
Cloud Security

The Hackers Got Hacked: Inside the Klue Breach and What It Means for Every Business Using Cloud Software

A forgotten service account let criminals walk into a competitive-intelligence platform. Then a second criminal group stole the stolen data. The whole chain shows exactly how cloud software trust goes wrong.

4 min read
An office worker's computer screen showing multiple cloud application windows open simultaneously with sensitive customer data visible in each, filing cabinets
Cloud Security

Your Company Uses Hundreds of Cloud Apps. Security Teams Can See Inside Almost None of Them.

Three real breaches show how misconfigured software-as-a-service tools leak customer records, private messages, and source code, all without anyone breaking down a single door.

4 min read
Illustration: a dimly lit corporate server room with soft blue rack lights
Identity & Access

Hackers Are Faking OAuth App IDs to Quietly Test Stolen Microsoft Logins

A new trick lets attackers check stolen Microsoft Entra ID passwords without triggering a single sign-in alert.

4 min read
Illustration: a modern office at dusk, glass doors held slightly open with a keycard dangling from a lanyard on the handle
Identity & Access

How ShinyHunters walked into Salesforce accounts without breaking anything

Microsoft says a year of data theft from Salesforce tenants leaned on trusted app connections, not a platform bug.

3 min read
Illustration: A dimly lit server room with rows of glowing rack-mounted servers
Vulnerabilities

A Hidden Door in RabbitMQ Left Company Systems Wide Open for Two Years

A flaw in the popular messaging software handed anyone on the network a master key to company data. Patches are out. Use them now.

3 min read
Illustration: a dense tangle of illuminated fibre-optic cables running through a dark server room
Vulnerabilities

Two Security Flaws in RabbitMQ Could Let Attackers Steal Login Secrets and Take Over Corporate Messaging Systems

A widely used software tool that moves data between business applications has patched two vulnerabilities, one of which could hand criminals full control over the system without a password.

3 min read
Illustration: a dim server room aisle at night, rows of dark server racks with faint green and amber status lights
Threat Intelligence

Old, Silent GitHub Accounts Are Being Used to Quietly Map Companies

Datadog Security Labs says several overlapping scraping campaigns are cataloguing corporate GitHub organisations using dormant 'ghost' accounts and stolen tokens.

3 min read
Illustration: a server rack's blinking status lights in a darkened data centre
Identity & Access

81 Million Login Attempts: A Massive Password Spray Attack Hit Microsoft 365 Users

Criminals hammered Microsoft accounts with automated login attempts for two weeks. At least 78 accounts were broken into, and some victims had multi-factor authentication switched on but not configured to cover the login route the attackers actually used.

3 min read
Illustration: a laptop screen showing a generic blurred cloud sign-in prompt
Identity & Access

Drag, Drop, Hijacked: How 'ConsentFix' Steals Microsoft 365 Sessions in Seconds

A new twist on the ClickFix trick turns Microsoft's own sign-in prompts into a session-theft machine, and a step-by-step guide is now circulating on a Russian crime forum.

4 min read
Illustration: a darkened data center corridor with a single amber warning light reflecting off polished server racks
Threat Intelligence

ToddyCat's New Umbrij Malware Pulls Gmail Straight From Google's API

Kaspersky ties the China-nexus crew to a Gmail-siphoning tool that skips the browser and talks to Google directly.

3 min read
Illustration: A dimly lit corporate office at night
Identity & Access

Device Code Phishing Is Eating MFA. Behavioral Detection Is the Backstop.

Token theft and consent-grant abuse sidestep the second factor entirely. Defenders are leaning on anomaly detection because the login looks legitimate.

3 min read
© 2026 Threat Vectr