🔓 OAuth Consent: Red Team’s Backdoor Into Azure This is how a cloud tenant falls, with barely a ripple. A pristine “Consent to application” event, quietly stamped as “Success.” #AzureAD #RedTeam #OAuthAbuse #Backdoor #PrivilegeEscalation #CloudOffense

GuardzCyber's tweet image. 🔓 OAuth Consent: Red Team’s Backdoor Into Azure

This is how a cloud tenant falls, with barely a ripple.
A pristine “Consent to application” event, quietly stamped as “Success.”

#AzureAD #RedTeam #OAuthAbuse #Backdoor #PrivilegeEscalation #CloudOffense

⚠️ Attackers abused stolen OAuth tokens from Salesloft’s Drift integration to tap into Salesforce orgs — pulling AWS keys, passwords, Snowflake tokens & more. Read more: dailysecurityreview.com/cyber-security… #OAuthAbuse #CloudSecurity #SaaSAttack #InfoSec

securitydailyr's tweet image. ⚠️ Attackers abused stolen OAuth tokens from Salesloft’s Drift integration to tap into Salesforce orgs — pulling AWS keys, passwords, Snowflake tokens & more. 

Read more: dailysecurityreview.com/cyber-security…

#OAuthAbuse #CloudSecurity #SaaSAttack #InfoSec

4/8 Once inside, attackers modify mailbox rules to cover their tracks, steal sensitive data, and register new OAuth applications for persistent access. The education sector has been hit the hardest due to the weak security of student accounts. 📬🎓 #DataTheft #OAuthAbuse


Scattered Lapsus$ Hunters, an alliance of Scattered Spider, LAPSUS$, and ShinyHunters, hit 91 firms including Adidas, Cartier, Google, and Louis Vuitton via social engineering and OAuth abuse in 2025. #DataTheft #OAuthAbuse #USA ift.tt/GkAaKy8


Happy to see @azuread @office365 taking some steps to make application information more transparent at consent time. Specifying an application is not an official app and is unverified is a great step to reducing #oauthabuse #dfir #o365 #office365

doughsec's tweet image. Happy to see @azuread @office365 taking some steps to make application information more transparent at consent time. Specifying an application is not an official app and is unverified is a great step to reducing #oauthabuse #dfir #o365 #office365

Persistent threats are gaining stealthy access through stolen OAuth tokens—bypassing traditional security controls. Veritech outlines mitigation strategies to safeguard cloud assets: 🔗 veritech.consulting/june-2025-cybe… #CloudSecurity #ZeroTrust #OAuthAbuse #APTDefense


@SecBarbie you also fell for the twifficiency I see? #OAuthabuse


Thinking about it, I took @fun140 quiz weeks ago, how are they able to force my account to follow them so long after??? #oAuthAbuse


1/4 @Google taking some important steps to safeguard *consumer accounts* and prevent #OauthAbuse. Importantly these new protections do not cover Enterprise (G Suite) environments - arguably the accounts that are most at risk blog.google/technology/saf…


⚠️ Attackers abused stolen OAuth tokens from Salesloft’s Drift integration to tap into Salesforce orgs — pulling AWS keys, passwords, Snowflake tokens & more. Read more: dailysecurityreview.com/cyber-security… #OAuthAbuse #CloudSecurity #SaaSAttack #InfoSec

securitydailyr's tweet image. ⚠️ Attackers abused stolen OAuth tokens from Salesloft’s Drift integration to tap into Salesforce orgs — pulling AWS keys, passwords, Snowflake tokens & more. 

Read more: dailysecurityreview.com/cyber-security…

#OAuthAbuse #CloudSecurity #SaaSAttack #InfoSec

Scattered Lapsus$ Hunters, an alliance of Scattered Spider, LAPSUS$, and ShinyHunters, hit 91 firms including Adidas, Cartier, Google, and Louis Vuitton via social engineering and OAuth abuse in 2025. #DataTheft #OAuthAbuse #USA ift.tt/GkAaKy8


🔓 OAuth Consent: Red Team’s Backdoor Into Azure This is how a cloud tenant falls, with barely a ripple. A pristine “Consent to application” event, quietly stamped as “Success.” #AzureAD #RedTeam #OAuthAbuse #Backdoor #PrivilegeEscalation #CloudOffense

GuardzCyber's tweet image. 🔓 OAuth Consent: Red Team’s Backdoor Into Azure

This is how a cloud tenant falls, with barely a ripple.
A pristine “Consent to application” event, quietly stamped as “Success.”

#AzureAD #RedTeam #OAuthAbuse #Backdoor #PrivilegeEscalation #CloudOffense

4/8 Once inside, attackers modify mailbox rules to cover their tracks, steal sensitive data, and register new OAuth applications for persistent access. The education sector has been hit the hardest due to the weak security of student accounts. 📬🎓 #DataTheft #OAuthAbuse


Happy to see @azuread @office365 taking some steps to make application information more transparent at consent time. Specifying an application is not an official app and is unverified is a great step to reducing #oauthabuse #dfir #o365 #office365

doughsec's tweet image. Happy to see @azuread @office365 taking some steps to make application information more transparent at consent time. Specifying an application is not an official app and is unverified is a great step to reducing #oauthabuse #dfir #o365 #office365

1/4 @Google taking some important steps to safeguard *consumer accounts* and prevent #OauthAbuse. Importantly these new protections do not cover Enterprise (G Suite) environments - arguably the accounts that are most at risk blog.google/technology/saf…


@SecBarbie you also fell for the twifficiency I see? #OAuthabuse


Thinking about it, I took @fun140 quiz weeks ago, how are they able to force my account to follow them so long after??? #oAuthAbuse


لا توجد نتائج لـ "#oauthabuse"

🔓 OAuth Consent: Red Team’s Backdoor Into Azure This is how a cloud tenant falls, with barely a ripple. A pristine “Consent to application” event, quietly stamped as “Success.” #AzureAD #RedTeam #OAuthAbuse #Backdoor #PrivilegeEscalation #CloudOffense

GuardzCyber's tweet image. 🔓 OAuth Consent: Red Team’s Backdoor Into Azure

This is how a cloud tenant falls, with barely a ripple.
A pristine “Consent to application” event, quietly stamped as “Success.”

#AzureAD #RedTeam #OAuthAbuse #Backdoor #PrivilegeEscalation #CloudOffense

⚠️ Attackers abused stolen OAuth tokens from Salesloft’s Drift integration to tap into Salesforce orgs — pulling AWS keys, passwords, Snowflake tokens & more. Read more: dailysecurityreview.com/cyber-security… #OAuthAbuse #CloudSecurity #SaaSAttack #InfoSec

securitydailyr's tweet image. ⚠️ Attackers abused stolen OAuth tokens from Salesloft’s Drift integration to tap into Salesforce orgs — pulling AWS keys, passwords, Snowflake tokens & more. 

Read more: dailysecurityreview.com/cyber-security…

#OAuthAbuse #CloudSecurity #SaaSAttack #InfoSec

Happy to see @azuread @office365 taking some steps to make application information more transparent at consent time. Specifying an application is not an official app and is unverified is a great step to reducing #oauthabuse #dfir #o365 #office365

doughsec's tweet image. Happy to see @azuread @office365 taking some steps to make application information more transparent at consent time. Specifying an application is not an official app and is unverified is a great step to reducing #oauthabuse #dfir #o365 #office365

Loading...

Something went wrong.


Something went wrong.


United States Trends