OAuth Client ID Spoofing Exploits Blind Spot in Microsoft Entra ID to Validate Stolen Credentials
Proofpoint has uncovered a novel evasion technique called OAuth client ID spoofing, exploited by at least two threat actors to validate stolen…
Latest cybersecurity news, breaches, vulnerability disclosures and industry developments.
Proofpoint has uncovered a novel evasion technique called OAuth client ID spoofing, exploited by at least two threat actors to validate stolen…
Security researcher cereblab discovered that xAI's Grok Build coding CLI (version 0.2.93) was uploading entire Git repositories—including full commit history—to a Google…
The U.S. Treasury Department's OFAC has sanctioned First VPN Service (1VPNS), its Ukrainian administrator Dmytro Rashevskyi, and Belarusian national Yegeniy Vladimirovich Silayev…
Google and Microsoft have removed the ModHeader browser extension from their respective web stores after security researchers discovered a dormant browsing-history collector…
This week's cybersecurity landscape is marked by a series of critical threats and vulnerabilities. Progress has urged ShareFile customers to shut down…
A new attack named MemGhost demonstrates how a single email can inject persistent false memories into AI personal assistants, manipulating their future…
Meta has filed a patent application (US 2026/0182881) for an AI system that continuously listens to a user's voice throughout the day,…
A new phishing-as-a-service (PhaaS) operation called Forg365 is targeting Microsoft 365 accounts using device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, AI-assisted…
A recent article on The Hacker News draws a compelling parallel between Daniel Kahneman's 'Thinking, Fast and Slow' and modern Security Operations…
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing…