#oauth


Klue OAuth breach victim list grows as Icarus hackers claim attack

Jun 20, 2026 // 01:36

Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers’ Salesforce […]

Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data

Jun 19, 2026 // 12:11

Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company […]

Klue OAuth breach linked to ‘Icarus’ Salesforce data theft attacks

Jun 18, 2026 // 19:37

Market intelligence platform Klue suffered a OAuth breach that enabled the “Icarus” threat actors to steal Salesforce CRM data from multiple organizations in an ongoing […]

One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens

Jun 4, 2026 // 14:56

Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user’s GitHub token. “Just […]

One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens

Jun 3, 2026 // 16:04

Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user’s GitHub token. “Just […]

⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More

Jun 1, 2026 // 22:14

Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some “patched-ish” thing already getting chewed on […]

The New Phishing Click: How OAuth Consent Bypasses MFA

May 19, 2026 // 14:34

In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five […]

ConsentFix v3 attacks target Azure with automated OAuth abuse

May 2, 2026 // 21:59

A new attack type, dubbed ConsentFix v3, has been circulating on hacker forums as an improved technique that automates attacks against Microsoft Azure. The first […]

Learning from the Vercel breach: Shadow AI & OAuth sprawl

Apr 29, 2026 // 16:16

Most organizations are rightly nervous about employees adopting unapproved AI tools. Shadow AI use in the form of LLMs, where users upload sensitive data to […]

OAuth abuse enables device code phishing attacks, impacting over 340 Microsoft 365 organizations across five countries.

Mar 25, 2026 // 14:43

Cybersecurity experts are raising awareness about an ongoing phishing scheme using device codes to compromise Microsoft 365 accounts in over 340 organizations across the U.S., […]