A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log […]
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, […]
A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users’ Twitch OAuth session tokens to a […]
Google Workspace attackers don’t necessarily need to exploit a software vulnerability or steal a user’s password to gain access to an organization’s data. On September […]
A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. […]
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” […]
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, […]
Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, […]
At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The […]
The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that’s designed to gain surreptitious access to a victim’s email […]
© Bulletproof Servers. All rights reserved.