oauth
3 stories
MFA Ineffective Against OAuth Consent Abuse Without Governance
Multi-factor authentication is a critical security layer, but it does not prevent threats arising from OAuth consent abuse. Robust OAuth governance, including the principle of least privilege for scopes, vigilant consent monitoring, and swift revocation capabilities, are necessary to mitigate these risks.

Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics
Google's Threat Intelligence Group has identified three Russian-linked cyber espionage clusters (UNC6293, UNC7005, and UNC5976) employing sophisticated social engineering tactics. These groups exploit legitimate authentication features like OAuth and app passwords to compromise accounts of researchers, diplomats, and defense personnel. They utilize fake conference invitations, spoofed login pages, and even leverage AI-generated code for malware, posing a significant challenge to traditional security monitoring.

When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website
Attackers are exploiting a legitimate Microsoft authentication feature, the Device Authorization Grant, to conduct phishing attacks. This method bypasses traditional URL checking by directing users to input codes on trusted Microsoft domains. The attack leverages the protocol designed for input-constrained devices, tricking users into authorizing malicious access.