< ciso
brief />
Tag Banner

All news with #oauth app abuse tag

77 articles

Why device code phishing became an industrial threat

🔒 Device code phishing — the abuse of the OAuth 2.0 device authorization grant — has rapidly evolved from a niche red-team tactic into a widespread criminalized attack. Exploiting the authorization step after authentication, it defeats all forms of MFA and has been commercialized in phishing-as-a-service kits. Push Security researchers outline the attack mechanics, ecosystem growth, cross-platform risk, and detection challenges for defenders.
read more →

Phishing Abuses Microsoft Trusted Login Flow

🛡️ Check Point researchers observed a widespread phishing campaign from June 25 through mid-July that impersonated Microsoft Teams notifications and directed recipients to genuine Microsoft sign-in pages. Victims were prompted to grant permissions to attacker-controlled applications, allowing abuse of the OAuth consent flow to access mail, files, Teams, SharePoint, OneDrive, and calendars. The campaign targeted roughly 120 organizations across multiple sectors and geographies before it ended.
read more →

Klue Breach Reveals New Third‑Party Identity Risks

🔒 The 2026 Klue compromise began as a SaaS supply‑chain breach and escalated when a second criminal group claimed to have stolen data from the initial extortion crew. Attackers exploited a forgotten service account and harvested OAuth tokens, enabling broad Salesforce API access and extensive data extraction. The incident underscores how identity and delegated application permissions now constitute the primary attack surface, challenging traditional perimeter defenses and ransom decision models.
read more →

ConsentFix: OAuth-based Microsoft 365 account hijacking

🛡️Researchers uncovered a new ClickFix variant called ConsentFix that tricks users into granting OAuth tokens, enabling attackers to access Microsoft 365 accounts without stealing passwords. Attackers use deceptive pages and social engineering—often via phishing emails imitating file-sharing services—to induce victims to drag a tokenized URL onto an attacker-controlled page. Once obtained, the OAuth token can expose Outlook, Teams, OneDrive, SharePoint and other services depending on the organization’s license and privileges, enabling data exfiltration, BEC and lateral movement. The technique is widely shared on cybercrime forums with tutorials and turnkey tools, increasing its prevalence and lowering the barrier for novice threat actors.
read more →

Shadow Token via Remote Debug: OAuth mailbox hijack

🔒 Kaspersky researchers describe a covert technique named Shadow Token via Remote Debug (STRD) used by the ToddyCat APT to gain persistent access to Google Workspace mailboxes without user interaction. The attackers deploy malware (Umbrij) that duplicates a browser profile, launches a headless debugging browser, and programmatically authorizes a third-party OAuth app to obtain an access token. This approach can survive password resets and evades endpoint detection when properly executed.
read more →

Microsoft maps year-long OAuth access campaigns

🔎 Microsoft mapped a year-long series of campaigns, running mid-2025 to mid-2026, that gave attackers access to corporate Salesforce environments without exploiting platform bugs. The intrusions relied on OAuth trust: vishing to approve malicious connected apps, theft of vendor OAuth tokens, and misconfigured guest access to Experience Cloud. Microsoft and Salesforce added detection and governance features in Defender for Cloud Apps and improved real-time event visibility to expose connected-app activity and reduce over-permissioned integrations.
read more →

Defending SaaS OAuth Abuse Targeting Salesforce

🔒 Microsoft observed campaigns from mid-2025 to mid-2026 where actors using tradecraft linked to ShinyHunters abused OAuth trust relationships to access Salesforce instances, exfiltrate CRM data, and maintain persistence. Three intrusion paths were identified: vishing-induced OAuth consent, supply-chain compromises of integrations (e.g., Salesloft, Gainsight), and misconfigured guest access via Aura/GraphQL. Microsoft enhanced Defender for Cloud Apps telemetry and controls, coordinated with Salesforce, and introduced posture, visibility, and risk-scoring features to help detect and mitigate these threats.
read more →

ConsentFix and ClickFix: Microsoft 365 hijacks

🔒 Modern phishing variants like ClickFix and the newer ConsentFix convert routine user actions into account takeover opportunities. Attackers trick victims into executing keyboard shortcuts or dragging callback links, which hands over OAuth tokens and session access to Microsoft 365 services without passwords or MFA bypass. The technique relies on familiar workflows and readily available tooling, with public sharing of blueprints lowering the barrier to entry.
read more →

Klue OAuth breach expands as Icarus claims attack

🔒 Klue confirmed an incident on June 12 in which attackers used a compromised legacy credential to obtain OAuth tokens connecting Klue to third-party platforms, including Salesforce. The company says customer content stored in Klue was not impacted and that the breach was limited to integrations; affected credentials and tokens were revoked and CrowdStrike engaged. Cybersecurity firms ReliaQuest and Huntress reported extensive Salesforce data exfiltration, and the Icarus extortion group has publicly claimed responsibility.
read more →

EvilTokens phishing abuses OAuth device code flow

🛡️ EvilTokens is a phishing-as-a-service kit that compromises Microsoft 365 accounts by abusing the OAuth 2.0 device authorization grant flow, tricking victims into authorizing attacker sessions via legitimate Microsoft login pages. Active since at least February 2026, the toolkit has been used in large account takeover and BEC campaigns, leveraging reconnaissance and decoy lures to obtain access and refresh tokens. Because victims complete real authentication — including 2FA — the attacks bypass traditional red flags like fake login pages. Organizations are advised to restrict device code flow, monitor unusual token activity, and update security awareness to address these modern phishing tactics.
read more →

GitHub browser VSCode flaw risks stolen developer tokens

🛡️ A researcher disclosed a vulnerability in GitHub’s browser-based VSCode (github.dev) that could allow an attacker to obtain a developer’s OAuth token and access any repos the developer can reach. The issue involves github.com POSTing a broad-scoped token to github.dev and a bypass in Jupyter notebook-based extension installation that can exfiltrate the token. Microsoft implemented a short-term mitigation requiring notebook confirmation and restoring the trusted-publisher check.
read more →

One-click GitHub.dev attack exposes OAuth tokens

🔒 Security researchers disclosed a one-click attack targeting GitHub.dev in the browser-hosted VS Code environment that can steal a user's GitHub OAuth token. The exploit abuses message passing between the main VS Code window and untrusted webviews to simulate keypresses, open the Command Palette, and install malicious extensions. By leveraging local workspace extensions and configurable keybindings, attackers can bypass trust prompts and extract tokens with access to private repositories. Microsoft has acknowledged the issue and is working on a fix; the vulnerability does not affect VS Code Desktop.
read more →

VS Code zero-day lets attackers steal GitHub tokens

🛡️ A security researcher published exploit code for a Visual Studio Code zero-day that enables attackers to steal GitHub OAuth tokens by tricking users into clicking a link. The flaw abuses VS Code's sandboxed webview message-passing to run JavaScript that simulates keypresses, installs a malicious extension, and exfiltrates tokens sent to github.dev. The vulnerability is unpatched and unassigned a CVE; users can mitigate risk by clearing cookies and site data for github.dev to force reauthentication prompts.
read more →

Shadow AI and the Rise of Vibe‑Coded Application Risk

🔎 Shadow AI now describes employees building full applications with AI and publishing them without IT or security involvement. Red Access' Shadow Builders report found over 380,000 public assets on vibe‑coding platforms, with more than 2,000 exposing sensitive corporate or personal data. Existing security controls miss these builds because the entire lifecycle — OAuth grants, data movement, and publishing — occurs inside web sessions that traditional tools only partially observe.
read more →

FBI warns of Kali365 phishing kit bypassing MFA

🔒 The FBI has alerted organisations to Kali365, a phishing-as-a-service platform that can hijack Microsoft 365 accounts without stealing passwords and can bypass multi-factor authentication. Launched in April 2026 and sold via Telegram, Kali365 offers AI-generated lures, automated templates, dashboards, and OAuth token capture for as little as $250 monthly. The kit exploits Microsoft’s device code flow, tricking victims into authorising attacker devices on legitimate Microsoft pages, granting access to Outlook, Teams, and OneDrive. The FBI recommends blocking device code flow with a conditional access policy in Microsoft Entra ID and deploying phishing-resistant MFA such as hardware security keys.
read more →

FBI Alerts on Kali365 Phishing Service Targeting M365

🔒 The FBI warns about the Kali365 phishing-as-a-service platform that abuses OAuth device code authentication to hijack Microsoft 365 and Microsoft Entra accounts. Distributed via Telegram since April 2026, Kali365 enables low-skilled attackers to bypass MFA by tricking victims into authorizing device codes, then capturing OAuth tokens to access mailboxes and cloud apps. Researchers observed campaigns using phishing emails, AI-generated lures, and real-time dashboards, while the FBI advises blocking device code flows and preserving forensic evidence.
read more →

FBI Warns of Kali365 Phishing-as-a-Service Threat

🛡️ The FBI has identified a new phishing-as-a-service platform called Kali365, first seen in April 2026, that is being distributed primarily via Telegram. The service furnishes AI-generated lures, automated templates and real-time tracking dashboards to enable attackers — including low-skill actors — to capture OAuth tokens and bypass MFA for Microsoft 365 accounts. Victims are tricked into pasting device codes into the legitimate Microsoft verification page, unintentionally authorizing attacker devices and granting persistent access to services such as Outlook, Teams and OneDrive. The FBI recommends restricting or blocking device code flow, implementing conditional access policies, blocking authentication transfer and protecting emergency access accounts.
read more →

FBI alert: Kali365 OAuth phishing risks rise

🔒 The FBI warns of phishing campaigns using Kali365 to harvest Microsoft 365 OAuth access tokens and bypass multi-factor authentication. Attackers trick users into entering a code on a legitimate Microsoft page, which instead authorizes the attacker’s device to access the victim’s account. The FBI advises IT teams to deploy conditional access policies and block authentication transfer to reduce exposure.
read more →

Detecting and Blocking Unsanctioned AI in the Enterprise

🔍 While many organizations intentionally deploy AI to improve productivity, unsanctioned AI is proliferating faster — employees install tools or vendors embed assistants into existing apps. The article defines four AI categories and maps specific detection techniques to each, covering DNS, web gateways/NGFW, EPP/EDR, application and browser controls, and SSPM/identity governance. It flags OAuth consent as a high-risk channel and summarizes admin steps for Microsoft Entra, Google Admin, Salesforce, and ServiceNow to block or restrict app access.
read more →

Consent Phishing: OAuth Grants Enable Token Hijacks

🔐 In February 2026 the EvilTokens PhaaS campaign abused the OAuth consent flow to harvest long‑lived refresh tokens, compromising over 340 Microsoft 365 organizations across five countries. Victims completed legitimate sign‑ins and MFA at microsoft.com/devicelogin, then clicked consent and unknowingly granted broad scopes for mail, drive, calendar, and contacts. Because the attacker received signed, refreshable tokens rather than credentials, MFA and typical SIEM correlation did not detect the intrusion. The incident demonstrates how normalized consent clicks have become a critical security gap.
read more →