OAuth stories
Proofpoint flags mailbox rule abuse in Microsoft 365
2 days ago
#
edutech
#
mfa
#
cloud security
Proofpoint says mailbox rule abuse is becoming a routine Microsoft 365 takeover tactic, helping attackers hide alerts, hijack threads and drive fraud.
Microsoft 365 EvilToken campaign hits hundreds daily
Last week
#
mfa
#
cloud security
#
phishing
Microsoft warns that 10 to 15 EvilToken phishing runs are launched daily, compromising hundreds of organisations through OAuth token abuse.
OpenID Foundation names Kantara as authorised auditor
Last month
#
fintech
#
iam
#
risk & compliance
OpenID Foundation appoints Kantara Initiative to oversee testing service applicants as it expands independent assurance for digital identity standards.
Vorlon launches tools for AI agent security response
Last month
#
data protection
#
cloud security
#
socs
Vorlon unveils AI Agent Flight Recorder and Action Centre to help security teams trace activity across SaaS apps and coordinate responses.
Vorlon survey finds SaaS AI security gaps among CISOs
Last month
#
data protection
#
cloud security
#
application security
Vorlon survey reveals nearly all CISOs suffered SaaS and AI security incidents in 2025, despite high confidence in existing controls.
CData boosts Connect AI with secure MCP agent tools
Last month
#
virtualisation
#
devops
#
data analytics
CData upgrades Connect AI with managed MCP tools, tightening data access, identity controls and live connectivity for enterprise agents.
OpenClaw AI assistant surge sparks major security fears
Fri, 27th Feb 2026
#
malware
#
phishing
#
application security
A rapid surge in OpenClaw AI assistant use has left tens of thousands of exposed systems and a trail of hijacked tools and malicious add-ons.
AI-fuelled cyber attacks now steal data in 72 minutes
Fri, 27th Feb 2026
#
firewalls
#
pam
#
cloud security
AI-driven hackers can now steal data in just 72 minutes, as faster, multi-surface attacks overwhelm complex, over-trusting enterprises.
Okta unveils tools to detect & govern shadow AI risks
Fri, 13th Feb 2026
#
pam
#
cloud security
#
application security
Okta launches Agent Discovery to uncover and rein in shadow AI agents, mapping risky app access and tightening identity-based controls.
Okta users warned as ShinyHunters expand vishing wave
Wed, 4th Feb 2026
#
ddos
#
ransomware
#
mfa
Okta users face rising vishing attacks as ShinyHunters expand real-time MFA phishing, prompting fresh SaaS and identity security warnings.
Shadow AI assistant Clawdbot raises workplace risks
Thu, 29th Jan 2026
#
uc
#
firewalls
#
data protection
Shadow AI tool Clawdbot quietly spreads across workplaces, alarming security teams as staff grant it broad access on unmanaged devices.
Experts warn AI era demands tougher data protection
Fri, 23rd Jan 2026
#
data protection
#
digital transformation
#
pam
Experts say AI-driven attacks and rampant data leaks mean organisations must verify outputs, curb collection and harden identity controls.
Kubernetes accelerates large-scale phishing operations
Tue, 13th Jan 2026
#
virtualisation
#
mfa
#
cloud security
Criminals are using Kubernetes and cloud-native tools to rapidly scale phishing-as-a-service, targeting Gmail, Facebook and Microsoft O365.
Proofpoint warns of surge in Microsoft device code phishing
Thu, 8th Jan 2026
#
edutech
#
mfa
#
cloud security
Proofpoint flags a sharp rise in Microsoft 365 account takeovers via device code phishing, hitting firms from finance to government.
SaaS attacks surge as boards turn to AI for defence
Thu, 25th Dec 2025
#
saas
#
crm
#
firewalls
Cyber attacks on SaaS platforms are soaring, pushing boards to make AI‑driven security a core strategy as misconfigurations fuel mass breaches.
CData, Microsoft unlock broad MCP data connectivity
Fri, 21st Nov 2025
#
data analytics
#
martech
#
ai security
CData's Connect AI now enables Microsoft Copilot Studio agents to access and act on live data from 350+ enterprise systems, boosting AI-driven business insights.
Weaponised OAuth apps allow persistent access to cloud accounts
Wed, 22nd Oct 2025
#
vpns
#
cloud security
#
phishing
Proofpoint reveals how weaponised OAuth apps enable hackers to maintain cloud access despite password resets and MFA, threatening persistent account takeover.
Google Workspace isn't built to handle shadow SaaS
Thu, 2nd Oct 2025
#
cloud security
#
casb
#
iam
Google Workspace's native tools struggle to manage unapproved SaaS apps, exposing firms to data risks amid rising shadow IT use.
Barracuda warns of surge in advanced OAuth phishing
Thu, 25th Sep 2025
#
firewalls
#
mfa
#
phishing
Barracuda warns of a surge in advanced OAuth phishing attacks exploiting Microsoft 365 and other platforms to steal access tokens and bypass multifactor authentication.
Delinea unveils open-source MCP Server to secure AI agent access
Wed, 24th Sep 2025
#
physical security
#
rpa
#
llms
Delinea has launched its open-source MCP Server, enabling secure, policy-driven access for AI agents to manage credentials and workflows efficiently.