Tag · 50 articles

OAuth

Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA

Learn about the rising threat of OAuth Device Code Phishing used by Tycoon 2FA operators to bypass MFA. Discover how to protect your systems and users.

Tycoon 2FA Adopts OAuth Device Code Attacks In MFA Bypass Campaign

Tycoon 2FA's recent adoption of OAuth Device Code attacks highlights critical security risks in MFA implementations. Learn how to protect your systems now.

Mozilla Thunderbird 151 Enables OAuth Sign-In with Account Auto-Configuration

Mozilla Thunderbird 151 introduces OAuth sign-in and account auto-configuration, enhancing security and user experience. Learn how to implement these features effectively.

The New Phishing Click: How OAuth Consent Bypasses MFA

Learn how attackers are using OAuth consent screens to bypass MFA and gain unauthorized access. Discover best practices to protect your applications and users.

AI Platform Dify Exposes Users to One-Click Account Takeover

Breaking: AI platform Dify with 10 million installs exposes users to one-click account takeover. Learn how this vulnerability affects security and what developers should do immediately.

How to Add Sign in with Vercel to Auth0

Learn how to integrate Sign in with Vercel into Auth0 for seamless authentication. Step-by-step guide with code examples and security tips included.

OAuth Risk Explained: Hidden Threats in SaaS

GitHub's OAuth token leak exposed 100K repos. Learn how OAuth risks can affect SaaS and how to secure your integrations immediately.

3 OAuth TTPs Seen This Month — and How to Detect Them with Entra ID Logs

Discover the latest OAuth TTPs and learn how to detect them using Entra ID logs. Protect your applications from attacks with practical security measures.

WorkOS Releases auth.md: An Open Agent Registration Protocol Built on OAuth Standards

WorkOS introduces auth.md, an open agent registration protocol based on OAuth standards. Learn how it simplifies identity management and enhances security in your applications.

FBI Warns of Kali Oauth Stealers

FBI warns of Kali Oauth stealers targeting OAuth vulnerabilities. Learn how to protect your applications and prevent unauthorized access.

FBI Warns Kali365 Phishing Kit Hijacks Microsoft 365 OAuth Tokens

FBI warns of Kali365 phishing kit targeting Microsoft 365 OAuth tokens. Learn how to protect your organization from this threat.

Post-Quantum Cryptography Migration for Identity Infrastructure: 2026 Developer Guide

Migrate your identity infrastructure to post-quantum cryptography before the 2030 federal deadline. Covers NIST ML-KEM/ML-DSA standards, Keycloak PQC JWT signing, TLS hybrid migration, and JWT/SAML signing for OAuth 2.0 systems.

The Credential Crisis: How Stolen Credentials Defeat Modern Security

The Credential Crisis exposes vulnerabilities in modern security practices. Learn how stolen credentials can defeat even the most robust defenses and how to protect your systems.

Entra ID Federation: External IDPs

Learn how to configure Microsoft Entra ID Federation with external identity providers for seamless SSO. Step-by-step guide with code examples and security tips.

Fake Party Invitation Phishing Scam Spoofs Google and Microsoft OAuth Logins: FTC Warns

Learn about the latest OAuth phishing scam targeting Google and Microsoft logins. Discover how to protect your applications and users from this threat.

OAuth Device Code Flow Security: How to Detect and Prevent Device Code Phishing

OAuth device code phishing (RFC 8628 abuse) bypasses MFA and steals M365 refresh tokens without a password. Learn how to disable device authorization grant in Entra ID, Keycloak, Auth0, and detect attacks with SIEM rules.

How Did a Stolen OAuth Token Bypass MFA in the $2M Supply Chain Attack?

Breaking: OAuth token breach affects Salesforce ecosystem. Learn what happened, who's impacted, and how to protect your integrations immediately.

GitHub Breach Explained: Repo Exposure, OAuth Risk & Supply Chain Attacks

GitHub's recent OAuth token leak exposed 100K+ repos. Learn what happened, who's impacted, and how to protect your integrations immediately.

Tycoon 2FA Returns With OAuth-Based Phishing to Bypass Microsoft 365 Security

Tycoon 2FA uses OAuth-based phishing to bypass Microsoft 365 security. Learn how to protect your organization from this emerging threat.

Microsoft Warns OAuth Redirect Abuse Delivers Malware to Government Targets

Microsoft warns of OAuth redirect abuse targeting government entities. Learn how to protect your systems from this critical security threat.