UNC5976: Russian Threat Actor Automating OAuth Token Theft via Cloud Infrastructure
UNC5976 is a suspected Russian threat actor active since at least March 2026, using OAuth phishing and automated token collection. It creates…
UNC5976 is a suspected Russian threat actor active since at least March 2026, using OAuth phishing and automated token collection. It creates…
Google OAuth is a legitimate authentication service that has been abused by Russian threat actors to steal authentication tokens and hijack accounts.…
New research presented at Black Hat USA 2026 reveals that CSS and HTML techniques can break out of email message boundaries to…
A paste race in Yahoo Mail and AOL Mail on Firefox can leak Medium email-login tokens, allowing account takeover.
The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has expanded its capabilities to include device code phishing, a technique that abuses the…
Greatness is a commercial phishing-as-a-service (PhaaS) toolkit that has evolved to include device code phishing, AiTM token theft, and OAuth consent abuse.…
Microsoft has disclosed a cyber espionage campaign, tracked as CaptiveCrunch, that abuses hijacked hotel Wi-Fi captive portals to deliver a remote access…
Kali365 is a device code phishing kit that targets US organizations by abusing legitimate Microsoft authentication. It lures victims with pages impersonating…
Umbrij is a .NET-based malware attributed to the ToddyCat APT group, designed to steal OAuth tokens from Gmail accounts. It exploits Chromium-based…
Gmail's image-set() fallback can be abused to make external requests, enabling exfiltration of Slack tokens through prompt injection in AI-connected email workflows.