Security News
data:image/s3,"s3://crabby-images/1bbc8/1bbc8a497266f4cc5e5a23d5296786d6003c880f" alt="Microsoft: OAuth apps used to automate BEC and cryptomining attacks"
Microsoft warns that financially-motivated threat actors are using OAuth applications to automate BEC and phishing attacks, push spam, and deploy VMs for cryptomining. Recent incidents investigated by Microsoft Threat Intelligence experts revealed that attackers mainly target user accounts that lack robust authentication mechanisms in phishing or password-spraying attacks, focusing on those with permissions to create or modify OAuth apps.
data:image/s3,"s3://crabby-images/dcec5/dcec5b114341b3506dfea65303f07f5a60e7bc95" alt="Critical OAuth Flaws Uncovered in Grammarly, Vidio, and Bukalapak Platforms"
Critical security flaws have been disclosed in the Open Authorization (OAuth) implementation of popular online services such as Grammarly, Vidio, and Bukalapak, building upon previous shortcomings...
data:image/s3,"s3://crabby-images/9a905/9a905f2a0f7266af9b981e44990674e2e6c86d6d" alt="How to Investigate an OAuth Grant for Suspicious Activity or Overly Permissive Scopes"
An even better practice would be to tailor your Google or Microsoft settings to require administrative approval for any new grant before employees can start using it, giving your team time to investigate and catch anything suspicious. While reviewing new OAuth grants can help you detect issues early on, oversight shouldn't end once an OAuth grant is in place.
data:image/s3,"s3://crabby-images/0375f/0375f4fb541f027b380046c456e15e2e0e69354c" alt="Serious Security: Verification is vital – examining an OAUTH login bug"
Researchers at web coding security company SALT just published a fascinating description of how they found an authentication bug dubbed CVE-2023-28131 in a popular online app-building coding toolkit known as Expo. Expo itself adds a wrapper around the verification process, so that it handles the authentication and the validation for you, ultimately passing a magic access token for the desired website back to the app or website you're connecting from.
data:image/s3,"s3://crabby-images/58963/5896369287811e9a3821b24990cb580e79ce3f01" alt="Critical OAuth Vulnerability in Expo Framework Allows Account Hijacking"
A critical security vulnerability has been disclosed in the Open Authorization implementation of the application development framework Expo.io. API security firm Salt Labs said the issue rendered services using the framework susceptible to credential leakage, which could then be used to hijack accounts and siphon sensitive data.
data:image/s3,"s3://crabby-images/32c0e/32c0ee688eda052d402f2947854de37850e44455" alt="Week in review: Rail transport cybersecurity, “verified” OAuth apps used to infiltrate organizations"
Week in review: Rail transport cybersecurity, “verified” OAuth apps used to infiltrate organizations
Mounting cybersecurity pressure is creating headaches in railway boardroomsIn this Help Net Security interview, Dimitri van Zantvliet is the Cybersecurity Director/CISO of Dutch Railways, and co-chair to the Dutch and European Rail ISAC, talks about cyber attacks on railway systems, build a practical cybersecurity approach, as well as cyber legislation. Attackers used malicious "Verified" OAuth apps to infiltrate organizations' O365 email accountsMalicious third-party OAuth apps with an evident "Publisher identity verified" badge have been used by unknown attackers to target organizations in the UK and Ireland, Microsoft has shared.
data:image/s3,"s3://crabby-images/b6a01/b6a01bd4ec729e4af386d8cc0d6dd3cf67008190" alt="Hackers Abused Microsoft's "Verified Publisher" OAuth Apps to Breach Corporate Email Accounts"
Microsoft on Tuesday said it took steps to disable fake Microsoft Partner Network accounts that were used for creating malicious OAuth applications as part of a malicious campaign designed to breach organizations' cloud environments and steal email.On top of that, Microsoft said it implemented additional security measures to improve the vetting process associated with the Microsoft Cloud Partner Program and minimize the potential for fraud in the future.
data:image/s3,"s3://crabby-images/f70d4/f70d4fa68f45ca978f2290e4f9477e2b775d6a38" alt="Microsoft disables verified partner accounts used for OAuth phishing"
Microsoft has disabled multiple fraudulent, verified Microsoft Partner Network accounts for creating malicious OAuth applications that breached organizations' cloud environments to steal email. In a joint announcement between Microsoft and Proofpoint, Microsoft says the threat actors posed as legitimate companies to enroll and successfully be verified as that company in the MCPP. The threat actors used these accounts to register verified OAuth apps in Azure AD for consent phishing attacks targeting corporate users in the UK and Ireland.
data:image/s3,"s3://crabby-images/d6216/d6216773cdb485b6a3660bc82e64f5c0497ee7fc" alt="Attackers used malicious “verified” OAuth apps to infiltrate organizations’ O365 email accounts"
Malicious third-party OAuth apps with an evident "Publisher identity verified" badge have been used by unknown attackers to target organizations in the UK and Ireland, Microsoft has shared. Targets in these organizations who have fallen for the trick effectively allowed these rogue apps to access to their O365 email accounts and infiltrate organizations' cloud environments.
data:image/s3,"s3://crabby-images/a49a1/a49a10f78c773efed7a5b4399996ea211b04e126" alt="Serious Security: OAuth 2 and why Microsoft is finally forcing you into it"
So if we're looking at HTTP Authentication, all we're really talking about is asking you to present a credential ,which is, for most of us, a username and password in order to gain access to something. "We're not going to tell you how to do it. We're going to say you should do one of these strong authentication methods, and then, once you know who you're talking to, we'll use OAuth to grant you a token that's independent of your proof of identity, that says what type of access you should have, and how long you should have it."