SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers

OAuth stories

Cloud server cluster hooks into laptop symbolizing mass phishing

Kubernetes accelerates large-scale phishing operations

Last week
#
oauth
Criminals are using Kubernetes and cloud-native tools to rapidly scale phishing-as-a-service, targeting Gmail, Facebook and Microsoft O365.
Office worker phishing qr code lock icon cloud account attack

Proofpoint warns of surge in Microsoft device code phishing

This month
#
oauth
Proofpoint flags a sharp rise in Microsoft 365 account takeovers via device code phishing, hitting firms from finance to government.
Ai shield protecting app icon cloud from shadowy cyber attack

SaaS attacks surge as boards turn to AI for defence

Last month
#
oauth
Cyber attacks on SaaS platforms are soaring, pushing boards to make AI‑driven security a core strategy as misconfigurations fuel mass breaches.
Interconnected data streams business software icons central ai symbol integration

CData, Microsoft unlock broad MCP data connectivity

Fri, 21st Nov 2025
#
oauth
CData's Connect AI now enables Microsoft Copilot Studio agents to access and act on live data from 350+ enterprise systems, boosting AI-driven business insights.
Cloud computing cybersecurity illustration shadowy figures accessing app icons

Weaponised OAuth apps allow persistent access to cloud accounts

Wed, 22nd Oct 2025
#
oauth
Proofpoint reveals how weaponised OAuth apps enable hackers to maintain cloud access despite password resets and MFA, threatening persistent account takeover.
Worried it professional chaotic unapproved cloud apps security risk

Google Workspace isn’t built to handle shadow SaaS

Thu, 2nd Oct 2025
#
oauth
Google Workspace’s native tools struggle to manage unapproved SaaS apps, exposing firms to data risks amid rising shadow IT use.
Realistic hacker at computer with digital symbols login screens microsoft 365 credential theft

Barracuda warns of surge in advanced OAuth phishing

Thu, 25th Sep 2025
#
oauth
Barracuda warns of a surge in advanced OAuth phishing attacks exploiting Microsoft 365 and other platforms to steal access tokens and bypass multifactor authentication.
Locked server digital circuit ai agents secure access enterprise environment

Delinea unveils open-source MCP Server to secure AI agent access

Wed, 24th Sep 2025
#
oauth
Delinea has launched its open-source MCP Server, enabling secure, policy-driven access for AI agents to manage credentials and workflows efficiently.
Illustration computer screen padlocks shields digital browser windows cybersecurity

SquareX launches open-source toolkits to defend browsers

Fri, 8th Aug 2025
#
oauth
SquareX launches two open-source toolkits to help security teams simulate and defend against browser-based attacks that evade traditional enterprise defences.
Secure server room norwegian flags medical icons digital padlocks healthcare data

Norway adopts FAPI 2.0 to secure national healthcare data

Thu, 26th Jun 2025
#
oauth
Norway mandates FAPI 2.0 security protocol across its national healthcare network to enhance protection of patient data with banking-level safeguards.
Digital illustration secure cloud environment with ai agents protecting data

Okta launches Cross App Access to boost AI security in firms

Tue, 24th Jun 2025
#
oauth
Okta has launched Cross App Access to enhance enterprise AI security by giving IT teams central control and visibility over AI agent interactions with apps.
Digital security shield protecting interconnected app icons data streams

Outpost24 identifies key OAuth risks & best practice solutions

Sat, 21st Jun 2025
#
oauth
Outpost24 reveals seven common OAuth risks and offers best practices to help organisations prevent unauthorised access and data breaches through better token security.
Vector illustration cloud symbol with locked unlocked padlocks compromised accounts

Over 80,000 Microsoft Entra ID accounts hit by major takeover campaign

Thu, 12th Jun 2025
#
oauth
Over 80,000 Microsoft Entra ID accounts have been targeted in the UNK_SneakyStrike takeover campaign exploiting the TeamFiltration penetration testing tool.
Software engineer at desk with secure code and automation icons speed security

Harness launches IDP 2.0 to boost developer speed & security

Thu, 12th Jun 2025
#
oauth
Harness unveils IDP 2.0, enhancing developer speed and security with granular RBAC, real-time Git sync, and enterprise-scale usability.
Businesswoman computer interacting digital gears network icons ai business growth

Pax8 launches AI initiatives & rewards to boost MSP growth

Wed, 11th Jun 2025
#
oauth
Pax8 launches new AI initiatives, including a research report, learning programme, marketplace upgrades, and rewards to accelerate MSP growth in SMB transformation.
Techday f a85bdf80c45e6df2d026

Cloudflare & Anthropic team up to power secure AI app links

Fri, 2nd May 2025
#
oauth
Cloudflare partners with Anthropic to enable secure, real-time AI integrations with SaaS giants like Atlassian, Stripe, and PayPal using its new MCP toolkit.
Techday be55e6126da8fc2b47c5

Cyber threats to Microsoft 365 via HTTP client tools surge

Tue, 11th Feb 2025
#
oauth
A recent report by Proofpoint reveals that 78% of Microsoft 365 users faced account takeovers, with attackers adeptly using HTTP client tools like Axios.
Dashboard

Ping Identity Platform updated with new CX and IT automation

Wed, 20th Feb 2019
#
oauth
The new versions improve the user and administrative experience, while also aiming to meet enterprise needs to operate quickly and purposefully.
Phishing4

How phishing is evolving to outpace awareness

Thu, 1st Nov 2018
#
oauth
Phishing techniques are evolving, targeting cloud-based services like Gmail, deceiving users into granting API access and exposing sensitive data.
Facebookconnectpopup

Symantec - '100k Facebook apps may be leaking user data'

Wed, 11th May 2011
#
oauth
Symantec reveals up to 100k Facebook apps could be leaking user data, with millions of accounts potentially compromised.