LIVE · cybersecurity feed
Live wire
CVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingCVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCVE-2025-39682 · CISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

oauth

3 stories
oauth

MFA Ineffective Against OAuth Consent Abuse Without Governance

Multi-factor authentication is a critical security layer, but it does not prevent threats arising from OAuth consent abuse. Robust OAuth governance, including the principle of least privilege for scopes, vigilant consent monitoring, and swift revocation capabilities, are necessary to mitigate these risks.

espionagehigh

Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics

Google's Threat Intelligence Group has identified three Russian-linked cyber espionage clusters (UNC6293, UNC7005, and UNC5976) employing sophisticated social engineering tactics. These groups exploit legitimate authentication features like OAuth and app passwords to compromise accounts of researchers, diplomats, and defense personnel. They utilize fake conference invitations, spoofed login pages, and even leverage AI-generated code for malware, posing a significant challenge to traditional security monitoring.

phishinghigh

When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website

Attackers are exploiting a legitimate Microsoft authentication feature, the Device Authorization Grant, to conduct phishing attacks. This method bypasses traditional URL checking by directing users to input codes on trusted Microsoft domains. The attack leverages the protocol designed for input-constrained devices, tricking users into authorizing malicious access.