OAuth stories
Kubernetes accelerates large-scale phishing operations
Last week
#
oauth
Criminals are using Kubernetes and cloud-native tools to rapidly scale phishing-as-a-service, targeting Gmail, Facebook and Microsoft O365.
Proofpoint warns of surge in Microsoft device code phishing
This month
#
oauth
Proofpoint flags a sharp rise in Microsoft 365 account takeovers via device code phishing, hitting firms from finance to government.
SaaS attacks surge as boards turn to AI for defence
Last month
#
oauth
Cyber attacks on SaaS platforms are soaring, pushing boards to make AI‑driven security a core strategy as misconfigurations fuel mass breaches.
CData, Microsoft unlock broad MCP data connectivity
Fri, 21st Nov 2025
#
oauth
CData's Connect AI now enables Microsoft Copilot Studio agents to access and act on live data from 350+ enterprise systems, boosting AI-driven business insights.
Weaponised OAuth apps allow persistent access to cloud accounts
Wed, 22nd Oct 2025
#
oauth
Proofpoint reveals how weaponised OAuth apps enable hackers to maintain cloud access despite password resets and MFA, threatening persistent account takeover.
Google Workspace isn’t built to handle shadow SaaS
Thu, 2nd Oct 2025
#
oauth
Google Workspace’s native tools struggle to manage unapproved SaaS apps, exposing firms to data risks amid rising shadow IT use.
Barracuda warns of surge in advanced OAuth phishing
Thu, 25th Sep 2025
#
oauth
Barracuda warns of a surge in advanced OAuth phishing attacks exploiting Microsoft 365 and other platforms to steal access tokens and bypass multifactor authentication.
Delinea unveils open-source MCP Server to secure AI agent access
Wed, 24th Sep 2025
#
oauth
Delinea has launched its open-source MCP Server, enabling secure, policy-driven access for AI agents to manage credentials and workflows efficiently.
SquareX launches open-source toolkits to defend browsers
Fri, 8th Aug 2025
#
oauth
SquareX launches two open-source toolkits to help security teams simulate and defend against browser-based attacks that evade traditional enterprise defences.
Norway adopts FAPI 2.0 to secure national healthcare data
Thu, 26th Jun 2025
#
oauth
Norway mandates FAPI 2.0 security protocol across its national healthcare network to enhance protection of patient data with banking-level safeguards.
Okta launches Cross App Access to boost AI security in firms
Tue, 24th Jun 2025
#
oauth
Okta has launched Cross App Access to enhance enterprise AI security by giving IT teams central control and visibility over AI agent interactions with apps.
Outpost24 identifies key OAuth risks & best practice solutions
Sat, 21st Jun 2025
#
oauth
Outpost24 reveals seven common OAuth risks and offers best practices to help organisations prevent unauthorised access and data breaches through better token security.
Over 80,000 Microsoft Entra ID accounts hit by major takeover campaign
Thu, 12th Jun 2025
#
oauth
Over 80,000 Microsoft Entra ID accounts have been targeted in the UNK_SneakyStrike takeover campaign exploiting the TeamFiltration penetration testing tool.
Harness launches IDP 2.0 to boost developer speed & security
Thu, 12th Jun 2025
#
oauth
Harness unveils IDP 2.0, enhancing developer speed and security with granular RBAC, real-time Git sync, and enterprise-scale usability.
Pax8 launches AI initiatives & rewards to boost MSP growth
Wed, 11th Jun 2025
#
oauth
Pax8 launches new AI initiatives, including a research report, learning programme, marketplace upgrades, and rewards to accelerate MSP growth in SMB transformation.
Cloudflare & Anthropic team up to power secure AI app links
Fri, 2nd May 2025
#
oauth
Cloudflare partners with Anthropic to enable secure, real-time AI integrations with SaaS giants like Atlassian, Stripe, and PayPal using its new MCP toolkit.
Cyber threats to Microsoft 365 via HTTP client tools surge
Tue, 11th Feb 2025
#
oauth
A recent report by Proofpoint reveals that 78% of Microsoft 365 users faced account takeovers, with attackers adeptly using HTTP client tools like Axios.
Ping Identity Platform updated with new CX and IT automation
Wed, 20th Feb 2019
#
oauth
The new versions improve the user and administrative experience, while also aiming to meet enterprise needs to operate quickly and purposefully.
How phishing is evolving to outpace awareness
Thu, 1st Nov 2018
#
oauth
Phishing techniques are evolving, targeting cloud-based services like Gmail, deceiving users into granting API access and exposing sensitive data.
Symantec - '100k Facebook apps may be leaking user data'
Wed, 11th May 2011
#
oauth
Symantec reveals up to 100k Facebook apps could be leaking user data, with millions of accounts potentially compromised.