Oauth Vulnerabilities
The latest Oauth Vulnerabilities coverage — news, analysis, and updates from the WindowsNews.AI desk.
The 2025 Surge in Sophisticated Phishing Attacks Targeting Microsoft Accounts: Strategies and Defenses
In 2025, the battleground for digital security has shifted dramatically, with Microsoft account holders standing on the front lines of an escalating war against increasingly sophisticated phishing...
Patched CVE-2025-4679 in Synology ABM Exposed 50K+ Firms to OAuth Bypass
A recently discovered vulnerability in Synology’s Active Backup for Microsoft 365 (ABM) has sent shockwaves through the IT security community, exposing critical risks in SaaS backup solutions....
nOAuth Vulnerability: How 15,000+ SaaS Apps Are at Risk and What Enterprises Must Do Now
A critical authentication flaw in Microsoft’s Entra ID (formerly Azure Active Directory) has exposed over 15,000 SaaS applications to potential exploitation, raising alarms across the cybersecurity...
Critical OneDrive OAuth Flaw Lets Apps Access All User Files Silently
A newly discovered vulnerability in Microsoft OneDrive could allow malicious third-party apps to access sensitive user data through improperly configured OAuth permission scopes. This security flaw,...
New Cloud Attack Steals Microsoft Entra Refresh Tokens to Bypass MFA
New Cloud Attack Technique Bypasses MFA by Stealing Microsoft Entra Refresh Tokens A sophisticated new cloud attack technique has emerged, leveraging a manipulation of Microsoft Entra (formerly Azure...
Russian Hackers Exploit OAuth 2.0 in Microsoft 365 'Midnight Blizzard' Attack
The digital battlegrounds of cloud security witnessed a sophisticated escalation this summer as Russian state-sponsored hackers orchestrated a novel attack exploiting inherent weaknesses in OAuth 2.0...
Russian APT group APT28 weaponizes OAuth 2.0 against Ukraine, NGOs
In a chilling reminder of the evolving landscape of cyber warfare, Russian state-sponsored hackers have been exploiting vulnerabilities in OAuth 2.0 to conduct sophisticated cyber espionage campaigns...
Russian Hackers Exploit OAuth 2.0 to Compromise Microsoft 365 Accounts in 2025
Introduction In early 2025, cybersecurity researchers uncovered a series of sophisticated attacks orchestrated by Russian-linked threat actors targeting Microsoft 365 accounts. These adversaries...
Exploiting Trust: How Russian Hackers Hijacked Microsoft 365 Accounts via OAuth 2.0 in 2023
Introduction In 2023, cybersecurity researchers uncovered a series of sophisticated attacks orchestrated by Russian state-sponsored hackers targeting Microsoft 365 accounts. These adversaries...
Microsoft 365 OAuth Phishing: Key Threats and Zero Trust Defenses
Microsoft 365 has become a prime target for cybercriminals leveraging OAuth phishing attacks, a sophisticated form of credential theft that bypasses traditional security measures. These attacks...