#oauth


Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

Sep 29, 2026 // 13:10

A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log […]

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Sep 23, 2026 // 11:27

Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, […]

Twitch extension with 30K installs exposes users’ OAuth tokens

Sep 14, 2026 // 23:43

A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users’ Twitch OAuth session tokens to a […]

Webinar: How malicious OAuth apps can lead to Google Workspace breaches

Sep 14, 2026 // 15:17

Google Workspace attackers don’t necessarily need to exploit a software vulnerability or steal a user’s password to gain access to an organization’s data. On September […]

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

Sep 14, 2026 // 11:51

A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. […]

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

Sep 3, 2026 // 23:22

The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” […]

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Aug 20, 2026 // 23:44

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, […]

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata

Jul 14, 2026 // 16:57

Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, […]

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

Jul 14, 2026 // 14:27

At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The […]

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

Jul 2, 2026 // 16:06

The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that’s designed to gain surreptitious access to a victim’s email […]

1 2 3 Next