Tag · 50 articles
OAuth
Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA
Learn about the rising threat of OAuth Device Code Phishing used by Tycoon 2FA operators to bypass MFA. Discover how to protect your systems and users.
Tycoon 2FA Adopts OAuth Device Code Attacks In MFA Bypass Campaign
Tycoon 2FA's recent adoption of OAuth Device Code attacks highlights critical security risks in MFA implementations. Learn how to protect your systems now.
Mozilla Thunderbird 151 Enables OAuth Sign-In with Account Auto-Configuration
Mozilla Thunderbird 151 introduces OAuth sign-in and account auto-configuration, enhancing security and user experience. Learn how to implement these features effectively.
The New Phishing Click: How OAuth Consent Bypasses MFA
Learn how attackers are using OAuth consent screens to bypass MFA and gain unauthorized access. Discover best practices to protect your applications and users.
AI Platform Dify Exposes Users to One-Click Account Takeover
Breaking: AI platform Dify with 10 million installs exposes users to one-click account takeover. Learn how this vulnerability affects security and what developers should do immediately.
How to Add Sign in with Vercel to Auth0
Learn how to integrate Sign in with Vercel into Auth0 for seamless authentication. Step-by-step guide with code examples and security tips included.
OAuth Risk Explained: Hidden Threats in SaaS
GitHub's OAuth token leak exposed 100K repos. Learn how OAuth risks can affect SaaS and how to secure your integrations immediately.
3 OAuth TTPs Seen This Month — and How to Detect Them with Entra ID Logs
Discover the latest OAuth TTPs and learn how to detect them using Entra ID logs. Protect your applications from attacks with practical security measures.
WorkOS Releases auth.md: An Open Agent Registration Protocol Built on OAuth Standards
WorkOS introduces auth.md, an open agent registration protocol based on OAuth standards. Learn how it simplifies identity management and enhances security in your applications.
FBI Warns of Kali Oauth Stealers
FBI warns of Kali Oauth stealers targeting OAuth vulnerabilities. Learn how to protect your applications and prevent unauthorized access.
FBI Warns Kali365 Phishing Kit Hijacks Microsoft 365 OAuth Tokens
FBI warns of Kali365 phishing kit targeting Microsoft 365 OAuth tokens. Learn how to protect your organization from this threat.
Post-Quantum Cryptography Migration for Identity Infrastructure: 2026 Developer Guide
Migrate your identity infrastructure to post-quantum cryptography before the 2030 federal deadline. Covers NIST ML-KEM/ML-DSA standards, Keycloak PQC JWT signing, TLS hybrid migration, and JWT/SAML signing for OAuth 2.0 systems.
The Credential Crisis: How Stolen Credentials Defeat Modern Security
The Credential Crisis exposes vulnerabilities in modern security practices. Learn how stolen credentials can defeat even the most robust defenses and how to protect your systems.
Entra ID Federation: External IDPs
Learn how to configure Microsoft Entra ID Federation with external identity providers for seamless SSO. Step-by-step guide with code examples and security tips.
Fake Party Invitation Phishing Scam Spoofs Google and Microsoft OAuth Logins: FTC Warns
Learn about the latest OAuth phishing scam targeting Google and Microsoft logins. Discover how to protect your applications and users from this threat.
OAuth Device Code Flow Security: How to Detect and Prevent Device Code Phishing
OAuth device code phishing (RFC 8628 abuse) bypasses MFA and steals M365 refresh tokens without a password. Learn how to disable device authorization grant in Entra ID, Keycloak, Auth0, and detect attacks with SIEM rules.
How Did a Stolen OAuth Token Bypass MFA in the $2M Supply Chain Attack?
Breaking: OAuth token breach affects Salesforce ecosystem. Learn what happened, who's impacted, and how to protect your integrations immediately.
GitHub Breach Explained: Repo Exposure, OAuth Risk & Supply Chain Attacks
GitHub's recent OAuth token leak exposed 100K+ repos. Learn what happened, who's impacted, and how to protect your integrations immediately.
Tycoon 2FA Returns With OAuth-Based Phishing to Bypass Microsoft 365 Security
Tycoon 2FA uses OAuth-based phishing to bypass Microsoft 365 security. Learn how to protect your organization from this emerging threat.