Advertisement

RabbitMQ Flaws: OAuth Secret Leak & Cross-Tenant Data Exposure
Two RabbitMQ access control flaws enable OAuth secret leakage, cross-tenant data exposure, and potential messaging infrastructure takeover risks.

ToddyCat Uses Umbrij Malware to Target Gmail via Google API Abuse
Runtime Rebel reports on ToddyCat's Umbrij malware campaign, abusing OAuth and Google API to access corporate Gmail accounts. Learn detection and mitigation strategies.
Klue OAuth Breach: Icarus Threat Group Targets Salesforce
Klue confirms an OAuth token breach by the Icarus group, potentially exposing customer Salesforce environments. Learn how to secure your integrations.

Defeating Persistent OAuth Token Risks in Google and Microsoft Apps
Learn how persistent OAuth tokens create backdoors in AI tools and productivity apps. Discover strategies to detect and remediate long-lived token exposure.

OAuth Token Hijacking in AI Tools: Vercel Breach Analysis
An investigation into how stolen OAuth tokens from a Vercel employee's AI tool session led to unauthorized internal access and the risks of AI integration.

Tycoon Phishers Adopt Device Code Attacks to Bypass 2FA
Tycoon 2FA Phishers are now leveraging device code phishing to bypass multi-factor authentication, granting them unauthorized account access.
OpenAI Codex Vulnerability Exposed GitHub Tokens via OAuth Flaw
Researchers discovered a critical OpenAI Codex vulnerability allowing GitHub token theft via OAuth flaws, risking unauthorized access to private repositories.