Tag

#OAuth

37 stories taggedOAuth · page 3 of 3.

Illustration: a tangled bundle of glowing fiber-optic cables converging into a single dark server rack port
Identity & Access

Shadow AI Is an IAM Problem Now, Not a DLP Problem

The risk isn't what employees paste into ChatGPT. It's what tokens, scopes, and service accounts the AI agents they spin up are quietly holding.

3 min read
Illustration: a glowing blue cloud server rack with a single severed fiber-optic cable sparking
Cloud Security

Salesforce Cuts Klue Battlecards Tie-In After OAuth Token Compromise

The CRM giant pulled the competitive-intelligence app's integration on June 11, 2026 following a security incident that exposed connected customer data.

3 min read
Illustration: a developer workstation with a glowing monitor showing abstract blue code editor panels
Vulnerabilities

One-Click VS Code Flaw Exposed GitHub OAuth Tokens to Theft

A researcher-disclosed bug in Microsoft's browser-based VS Code variant let a single crafted link siphon tokens with read/write access to private repos.

3 min read
Illustration: A vast server room at night, rows of illuminated rack hardware stretching to a vanishing point
AI Security

Agentic AI Is Doing What a Thousand Breach Reports Couldn't: Getting Boards to Open the Checkbook

Autonomous agents, AI-generated code, and frontier models capable of offensive cyber ops are finally making cybersecurity a board-level business conversation, not just an IT line item.

3 min read
Illustration: a phishing attack targeting Microsoft 365 users, showing a hacker bypassing security measures
Identity & Access

Kali365 Phishing Kit Hijacks Microsoft OAuth Tokens to Silently Bypass MFA

The FBI has flagged a device-code phishing campaign powered by Kali365, a toolkit that steals OAuth tokens tied to Microsoft 365 accounts without ever touching a user's password.

3 min read
Illustration: cybersecurity experts analyzing a network map with highlighted compromised routers
Threat Intelligence

GRU Operators Drained Microsoft 365 Tokens by Rewriting DNS on 18,000 SOHO Routers

Forest Blizzard shifted from targeted router malware to mass DNS hijacking after a UK advisory in August, intercepting OAuth tokens on Outlook on the web.

3 min read
Illustration: a hacker targeting Microsoft 365 through OAuth
Identity & Access

FBI flags Kali365, the latest phishing kit pitched at draining Microsoft 365 tenants

The bureau says the subscription-priced service abuses OAuth device-code flows to lift session tokens and walk straight past MFA.

3 min read
© 2026 Threat Vectr