#abuse


ConsentFix v3 attacks target Azure with automated OAuth abuse

May 2, 2026 // 21:59

A new attack type, dubbed ConsentFix v3, has been circulating on hacker forums as an improved technique that automates attacks against Microsoft Azure. The first […]

Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks

May 1, 2026 // 17:32

Cybersecurity researchers are warning of two cybercrime groups that are carrying out “rapid, high-impact attacks” operating almost within the confines of SaaS environments, while leaving […]

ThreatsDay Bulletin: $290M DeFi Hack, macOS LoL Abuse, ProxySmart SIM Farms +25 New Stories

Apr 23, 2026 // 16:19

You scroll past one incident and see another that feels familiar, like it should have been fixed years ago, but it still works with small […]

Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks

Apr 16, 2026 // 14:10

A “novel” social engineering campaign has been observed abusing Obsidian, a cross-platform note-taking application, as an initial access vector to distribute a previously undocumented Windows […]

OAuth abuse enables device code phishing attacks, impacting over 340 Microsoft 365 organizations across five countries.

Mar 25, 2026 // 14:43

Cybersecurity experts are raising awareness about an ongoing phishing scheme using device codes to compromise Microsoft 365 accounts in over 340 organizations across the U.S., […]

Operation Alice: Police shut down 373K child sexual abuse material sites.

Mar 20, 2026 // 20:37

Operation Alice, an international effort by law enforcement, has taken down more than 373,000 dark web pages selling bogus child sexual abuse material (CSAM). The […]

FortiGate Ransomware, Citrix Hacking, MCP Abuse, LiveChat Phishing, and Other Threats.

Mar 19, 2026 // 17:33

ThreatsDay Bulletin is back on The Hacker News, and this week has a familiar unsettling feeling. It’s not overwhelming or catastrophic, but rather a collection […]

Microsoft Warns Governments of Malware Spread via OAuth Redirect Abuse

Mar 3, 2026 // 13:35

Microsoft has warned of phishing campaigns specifically targeting government and public-sector organizations by abusing OAuth redirection mechanisms to deliver malware. Key Details of the Campaign Mitigation and […]