Topic: oauth abuse
-
Hijacked OAuth Apps: Your Cloud's Secret Backdoor
Cybercriminals exploit internal OAuth applications to create persistent backdoors in corporate cloud systems, bypassing security measures like password resets and multi-factor authentication. Attackers deceive users into approving malicious OAuth apps or compromise admin accounts to create truste...
Read More » -
OAuth Redirects Exploited to Deliver Malware
A sophisticated phishing campaign exploits OAuth's error-handling to redirect users from legitimate login pages to attacker-controlled sites, bypassing standard security filters. The attacks use convincing business-themed email lures to trick users into clicking links that lead to credential thef...
Read More » -
Secure Your Web Edge: Stop Browser-Based Breaches Now
Modern web browsers are central to enterprise operations but also a major security vulnerability, increasingly targeted by cybercriminals for identity intrusions and data theft. A webinar on September 29th will explore how browsers are weaponized, covering attack methods like session hijacking an...
Read More » -
Hotel Wi-Fi malware targets Microsoft 365 logins
Microsoft attributed the CaptiveCrunch cyberattack on hotel and conference Wi-Fi networks to a sub-cluster of Russian state-sponsored group Midnight Blizzard (Storm-2945), which used DNS tampering and phishing to hijack Microsoft 365 credentials since at least May. The campaign deploys two malwar...
Read More »