#oauthabuse Suchergebnisse
🔓 OAuth Consent: Red Team’s Backdoor Into Azure This is how a cloud tenant falls, with barely a ripple. A pristine “Consent to application” event, quietly stamped as “Success.” #AzureAD #RedTeam #OAuthAbuse #Backdoor #PrivilegeEscalation #CloudOffense
⚠️ Attackers abused stolen OAuth tokens from Salesloft’s Drift integration to tap into Salesforce orgs — pulling AWS keys, passwords, Snowflake tokens & more. Read more: dailysecurityreview.com/cyber-security… #OAuthAbuse #CloudSecurity #SaaSAttack #InfoSec
Scattered Lapsus$ Hunters, an alliance of Scattered Spider, LAPSUS$, and ShinyHunters, hit 91 firms including Adidas, Cartier, Google, and Louis Vuitton via social engineering and OAuth abuse in 2025. #DataTheft #OAuthAbuse #USA ift.tt/GkAaKy8
4/8 Once inside, attackers modify mailbox rules to cover their tracks, steal sensitive data, and register new OAuth applications for persistent access. The education sector has been hit the hardest due to the weak security of student accounts. 📬🎓 #DataTheft #OAuthAbuse
Happy to see @azuread @office365 taking some steps to make application information more transparent at consent time. Specifying an application is not an official app and is unverified is a great step to reducing #oauthabuse #dfir #o365 #office365
Persistent threats are gaining stealthy access through stolen OAuth tokens—bypassing traditional security controls. Veritech outlines mitigation strategies to safeguard cloud assets: 🔗 veritech.consulting/june-2025-cybe… #CloudSecurity #ZeroTrust #OAuthAbuse #APTDefense
攻撃者が不正入手済みOAuthトークンを使い、Salesforce API経由で法人データへアクセス。通常認証不要で認証ログを回避し、スムーズにデータ窃取を実現。#OAuthAbuse #SalesforceAttack gbhackers.com/hackers-abuse-…
gbhackers.com
Hackers Abuse Compromised OAuth Tokens to Access and Steal Salesforce Corporate Data
Google Threat Intelligence Group (GTIG) has issued an advisory concerning a broad data theft operation targeting corporate Salesforce instances via the Drift integration.
Thinking about it, I took @fun140 quiz weeks ago, how are they able to force my account to follow them so long after??? #oAuthAbuse
1/4 @Google taking some important steps to safeguard *consumer accounts* and prevent #OauthAbuse. Importantly these new protections do not cover Enterprise (G Suite) environments - arguably the accounts that are most at risk blog.google/technology/saf…
⚠️ Attackers abused stolen OAuth tokens from Salesloft’s Drift integration to tap into Salesforce orgs — pulling AWS keys, passwords, Snowflake tokens & more. Read more: dailysecurityreview.com/cyber-security… #OAuthAbuse #CloudSecurity #SaaSAttack #InfoSec
Scattered Lapsus$ Hunters, an alliance of Scattered Spider, LAPSUS$, and ShinyHunters, hit 91 firms including Adidas, Cartier, Google, and Louis Vuitton via social engineering and OAuth abuse in 2025. #DataTheft #OAuthAbuse #USA ift.tt/GkAaKy8
攻撃者が不正入手済みOAuthトークンを使い、Salesforce API経由で法人データへアクセス。通常認証不要で認証ログを回避し、スムーズにデータ窃取を実現。#OAuthAbuse #SalesforceAttack gbhackers.com/hackers-abuse-…
gbhackers.com
Hackers Abuse Compromised OAuth Tokens to Access and Steal Salesforce Corporate Data
Google Threat Intelligence Group (GTIG) has issued an advisory concerning a broad data theft operation targeting corporate Salesforce instances via the Drift integration.
🔓 OAuth Consent: Red Team’s Backdoor Into Azure This is how a cloud tenant falls, with barely a ripple. A pristine “Consent to application” event, quietly stamped as “Success.” #AzureAD #RedTeam #OAuthAbuse #Backdoor #PrivilegeEscalation #CloudOffense
4/8 Once inside, attackers modify mailbox rules to cover their tracks, steal sensitive data, and register new OAuth applications for persistent access. The education sector has been hit the hardest due to the weak security of student accounts. 📬🎓 #DataTheft #OAuthAbuse
Happy to see @azuread @office365 taking some steps to make application information more transparent at consent time. Specifying an application is not an official app and is unverified is a great step to reducing #oauthabuse #dfir #o365 #office365
1/4 @Google taking some important steps to safeguard *consumer accounts* and prevent #OauthAbuse. Importantly these new protections do not cover Enterprise (G Suite) environments - arguably the accounts that are most at risk blog.google/technology/saf…
Thinking about it, I took @fun140 quiz weeks ago, how are they able to force my account to follow them so long after??? #oAuthAbuse
🔓 OAuth Consent: Red Team’s Backdoor Into Azure This is how a cloud tenant falls, with barely a ripple. A pristine “Consent to application” event, quietly stamped as “Success.” #AzureAD #RedTeam #OAuthAbuse #Backdoor #PrivilegeEscalation #CloudOffense
⚠️ Attackers abused stolen OAuth tokens from Salesloft’s Drift integration to tap into Salesforce orgs — pulling AWS keys, passwords, Snowflake tokens & more. Read more: dailysecurityreview.com/cyber-security… #OAuthAbuse #CloudSecurity #SaaSAttack #InfoSec
Happy to see @azuread @office365 taking some steps to make application information more transparent at consent time. Specifying an application is not an official app and is unverified is a great step to reducing #oauthabuse #dfir #o365 #office365
Something went wrong.
Something went wrong.
United States Trends
- 1. #AEWFullGear 61.3K posts
- 2. Klay 12.1K posts
- 3. #LasVegasGP 148K posts
- 4. Lando 77K posts
- 5. LAFC 11K posts
- 6. Samoa Joe 3,209 posts
- 7. Swerve 5,031 posts
- 8. Hangman 7,228 posts
- 9. Benavidez 14.3K posts
- 10. LJ Martin 1,050 posts
- 11. #byucpl N/A
- 12. Haney 26.5K posts
- 13. Verstappen 52K posts
- 14. Terry Crews 3,249 posts
- 15. Mark Briscoe 3,840 posts
- 16. Kimi 28.4K posts
- 17. Georgia Tech 6,539 posts
- 18. Westbrook 3,955 posts
- 19. Terry Smith 2,869 posts
- 20. Utah 22.2K posts