UNC5976: Russian Threat Actor Automating OAuth Token Theft via Cloud Infrastructure
UNC5976 is a suspected Russian threat actor active since at least March 2026, using OAuth phishing and automated token collection. It creates…
UNC5976 is a suspected Russian threat actor active since at least March 2026, using OAuth phishing and automated token collection. It creates…
Azure Service Fabric clusters hosted the multi-tenant DB Gateway component that was compromised in the CosmosEscape exploit chain. Customer databases were not…