<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #OAuth</title><description>Cybersecurity articles tagged #OAuth on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Russian Threat Clusters Abuse OAuth and WhatsApp for Espionage</title><link>https://runtimerebel.com/blog/russian-threat-clusters-abuse-oauth-and-whatsapp-for-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-threat-clusters-abuse-oauth-and-whatsapp-for-espionage</guid><description>Google Threat Intelligence reports three suspected Russian groups using OAuth phishing, Google app passwords, and WhatsApp device linking to hijack accounts.</description><pubDate>Sun, 23 Aug 2026 16:14:39 GMT</pubDate><category>APT29</category><category>Phishing</category><category>OAuth</category><category>Credential Theft</category><category>Malware</category></item><item><title>Modern Google Workspace Attack Chain: OAuth &amp; AI Agent Risks</title><link>https://runtimerebel.com/blog/modern-google-workspace-attack-chain-oauth-ai-agent-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/modern-google-workspace-attack-chain-oauth-ai-agent-risks</guid><description>The modern Google Workspace attack chain exploits OAuth grants, not just email. Understand how attackers and AI agents compromise accounts and secure your environment.</description><pubDate>Sat, 15 Aug 2026 08:16:26 GMT</pubDate><category>Google Workspace</category><category>OAuth</category><category>AI Agents</category><category>Account Takeover</category><category>Cloud Security</category></item><item><title>RabbitMQ Flaws: OAuth Secret Leak &amp; Cross-Tenant Data Exposure</title><link>https://runtimerebel.com/blog/rabbitmq-flaws-oauth-secret-leak-cross-tenant-data-exposure</link><guid isPermaLink="true">https://runtimerebel.com/blog/rabbitmq-flaws-oauth-secret-leak-cross-tenant-data-exposure</guid><description>Two RabbitMQ access control flaws enable OAuth secret leakage, cross-tenant data exposure, and potential messaging infrastructure takeover risks.</description><pubDate>Tue, 14 Jul 2026 17:20:57 GMT</pubDate><category>RabbitMQ</category><category>OAuth</category><category>Access Control</category><category>Message Broker</category><category>Data Leak</category><category>Security Flaw</category><category>Cross Tenant</category></item><item><title>ToddyCat Uses Umbrij Malware to Target Gmail via Google API Abuse</title><link>https://runtimerebel.com/blog/toddycat-uses-umbrij-malware-to-target-gmail-via-google-api-abuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/toddycat-uses-umbrij-malware-to-target-gmail-via-google-api-abuse</guid><description>Runtime Rebel reports on ToddyCat&apos;s Umbrij malware campaign, abusing OAuth and Google API to access corporate Gmail accounts. Learn detection and mitigation strategies.</description><pubDate>Thu, 02 Jul 2026 14:06:01 GMT</pubDate><category>ToddyCat</category><category>Umbrij</category><category>Malware</category><category>Gmail</category><category>Google API</category><category>OAuth</category><category>Email Compromise</category><category>Kaspersky</category></item><item><title>Klue OAuth Breach: Icarus Threat Group Targets Salesforce</title><link>https://runtimerebel.com/blog/klue-oauth-breach-icarus-threat-group-targets-salesforce</link><guid isPermaLink="true">https://runtimerebel.com/blog/klue-oauth-breach-icarus-threat-group-targets-salesforce</guid><description>Klue confirms an OAuth token breach by the Icarus group, potentially exposing customer Salesforce environments. Learn how to secure your integrations.</description><pubDate>Sat, 20 Jun 2026 01:00:14 GMT</pubDate><category>Klue</category><category>OAuth</category><category>Salesforce</category><category>Icarus</category><category>Data Breach</category><category>Token Theft</category><category>Supply Chain Attack</category></item><item><title>Defeating Persistent OAuth Token Risks in Google and Microsoft Apps</title><link>https://runtimerebel.com/blog/defeating-persistent-oauth-token-risks-in-google-and-microsoft-apps</link><guid isPermaLink="true">https://runtimerebel.com/blog/defeating-persistent-oauth-token-risks-in-google-and-microsoft-apps</guid><description>Learn how persistent OAuth tokens create backdoors in AI tools and productivity apps. Discover strategies to detect and remediate long-lived token exposure.</description><pubDate>Tue, 05 May 2026 16:39:22 GMT</pubDate><category>OAuth</category><category>Google Workspace</category><category>Microsoft 365</category><category>App Governance</category><category>Token Theft</category></item><item><title>OAuth Token Hijacking in AI Tools: Vercel Breach Analysis</title><link>https://runtimerebel.com/blog/oauth-token-hijacking-in-ai-tools-vercel-breach-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/oauth-token-hijacking-in-ai-tools-vercel-breach-analysis</guid><description>An investigation into how stolen OAuth tokens from a Vercel employee&apos;s AI tool session led to unauthorized internal access and the risks of AI integration.</description><pubDate>Tue, 21 Apr 2026 05:03:55 GMT</pubDate><category>OAuth</category><category>Vercel</category><category>AI Security</category><category>Session Hijacking</category><category>Token Theft</category></item><item><title>Tycoon Phishers Adopt Device Code Attacks to Bypass 2FA</title><link>https://runtimerebel.com/blog/tycoon-phishers-adopt-device-code-attacks-to-bypass-2fa</link><guid isPermaLink="true">https://runtimerebel.com/blog/tycoon-phishers-adopt-device-code-attacks-to-bypass-2fa</guid><description>Tycoon 2FA Phishers are now leveraging device code phishing to bypass multi-factor authentication, granting them unauthorized account access.</description><pubDate>Sat, 18 Apr 2026 00:42:05 GMT</pubDate><category>Phishing</category><category>2FA Bypass</category><category>Tycoon Phishing</category><category>Account Takeover</category><category>Device Code Phishing</category><category>OAuth</category></item><item><title>OpenAI Codex Vulnerability Exposed GitHub Tokens via OAuth Flaw</title><link>https://runtimerebel.com/blog/openai-codex-vulnerability-exposed-github-tokens-via-oauth-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-codex-vulnerability-exposed-github-tokens-via-oauth-flaw</guid><description>Researchers discovered a critical OpenAI Codex vulnerability allowing GitHub token theft via OAuth flaws, risking unauthorized access to private repositories.</description><pubDate>Tue, 31 Mar 2026 08:32:36 GMT</pubDate><category>OpenAI</category><category>Codex</category><category>GitHub</category><category>OAuth</category><category>Credential Theft</category></item></channel></rss>