LIVE · cybersecurity feed
Live wire
CVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingCVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCVE-2025-39682 · CISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
oauthmedium

MFA Ineffective Against OAuth Consent Abuse Without Governance

Multi-factor authentication is a critical security layer, but it does not prevent threats arising from OAuth consent abuse. Robust OAuth governance, including the principle of least privilege for scopes, vigilant consent monitoring, and swift revocation capabilities, are necessary to mitigate these risks.

zeroday.news ·

A recent report highlights a significant limitation in the effectiveness of multi-factor authentication (MFA) when confronted with OAuth consent abuse. While MFA is widely recognized as a crucial security control, it does not inherently protect against the specific vector of attack that leverages misused or over-privileged OAuth consents. This finding underscores that even with MFA in place, organizations remain vulnerable if their OAuth implementations lack proper governance.

The core issue stems from how OAuth consent abuse operates. Unlike traditional credential theft where MFA directly intervenes by requiring a second factor for authentication, consent abuse exploits the legitimate process by which users grant applications access to their data. An attacker, often through phishing or social engineering, can trick a user into authorizing a malicious application with overly broad permissions. Once consent is granted, the malicious application can access the user's data or perform actions on their behalf, even if the user's account is protected by MFA, because the access token itself is legitimate and was obtained through a user-sanctioned process.

This class of attack typically targets applications that integrate with third-party services, such as cloud platforms, productivity suites, or social media. When a user authorizes a new application, they are presented with a consent screen detailing the permissions (scopes) the application is requesting. If these scopes are excessive or if the user is deceived into granting consent to a malicious application, the attacker gains persistent access without needing to bypass MFA on subsequent interactions.

To effectively mitigate these risks, the report emphasizes the necessity of robust OAuth governance. This includes implementing the principle of least privilege for requested scopes, ensuring that applications only request the minimum permissions required for their functionality. Developers and administrators should carefully review and restrict the scopes an application can request, and users should be educated to scrutinize consent requests.

Furthermore, vigilant consent monitoring is crucial. Organizations need mechanisms to track and audit the OAuth consents granted by their users. This allows for the detection of unusual or suspicious consent grants, such as a user authorizing an unfamiliar application with highly privileged scopes. Swift revocation capabilities are also essential, enabling administrators to quickly revoke malicious or compromised OAuth tokens and limit the window of exposure.

In broader context, this finding reinforces the understanding that security is a multi-layered challenge. While MFA remains an indispensable defense against credential-based attacks, it is not a panacea. This incident highlights the growing importance of identity and access management (IAM) beyond just authentication, extending into the granular control and continuous monitoring of application permissions and user consents in modern, interconnected environments.

oauthmfacybersecurityaccess control
ShareXLinkedInWhatsAppFacebook

More News

view all →
nation-state

Security Affairs newsletter Round 595 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Google Gemini also Broke Out of Its Test Environment AI Helps Hackers Hijack OpenAI Staff Accounts Through […]

vulnerability

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,

CVE-2024-4405high

Malicious Extensions Hijack AI Browser Agents via Prompt Forcing

A new proof-of-concept attack named BragJack demonstrates how malicious browser extensions can hijack AI assistants within browsers like Chrome and Edge. The attack utilizes a technique called Prompt Forcing to gain control of these AI agents, successfully earning significant bug bounties and two CVEs.

security

TigerByte Cyber Emerges From Stealth With $3 Million in Funding

The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA. The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.

security

North Korean WaterPlum hackers infected 30,000 devices worldwide

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]

ransomware

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]