Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > OAuth
#OAuth

Actively Exploited F5 BIG-IP OAuth Zero-Day Enables Unauthenticated RCE

23 September 2026  |  dark6  |  Vulnerability

F5 is warning that attackers are exploiting a critical BIG-IP APM zero-day that can provide unauthenticated remote code execution on certain OAuth authorization-server deployments. Organizations should identify exposed...

>> read more

Inside GhostCode: The Phishing Kit That Turns MFA Approval Into Account Takeover

17 September 2026  |  dark6  |  Phishing

A newly identified phishing kit called GhostCode hijacks Microsoft 365 accounts by abusing the OAuth device-code sign-in flow, letting victims unknowingly approve an attacker's device during a completely...

>> read more

Malicious Twitch Extension Leaks OAuth Tokens From 30,000 Browser Users

15 September 2026  |  dark6  |  Malware

A Twitch helper extension installed by about 30,000 Chrome and Firefox users was found sending active account tokens through operator-controlled servers. The incident shows how a seemingly convenient...

>> read more

New ARToken Phishing Kit Abuses Microsoft’s OAuth Device Code Flow to Hijack Microsoft 365 Accounts

4 July 2026  |  dark6  |  Phishing

Cisco Talos has uncovered ARToken, a phishing panel that abuses Microsoft's device code sign-in flow to steal Microsoft 365 session tokens without a password or MFA prompt. The...

>> read more

Klue Supply Chain Hack Exposes Salesforce Data at Nine Cybersecurity Companies

23 June 2026  |  dark6  |  Databreach

A supply chain attack on market intelligence platform Klue has compromised Salesforce CRM data across at least nine organizations, including HackerOne, Huntress, and Recorded Future. The Icarus extortion...

>> read more

Hackers Can Hijack Claude Code MCP Traffic to Steal OAuth Tokens — No Patch Coming

8 June 2026  |  dark6  |  Cybercrime

Researchers at Mitiga Labs demonstrated a five-step npm supply chain attack that rewrites ~/.claude.json to redirect Claude Code MCP traffic through attacker-controlled infrastructure, silently capturing OAuth tokens for...

>> read more

1-Click GitHub Token Theft: VSCode Webview Flaw Exposes OAuth Tokens for All Private Repositories

3 June 2026  |  dark6  |  Vulnerability

A critical VSCode webview vulnerability lets attackers steal GitHub OAuth tokens with a single click, granting full access to all private repositories. Researcher Ammar Askar published a complete...

>> read more

Vercel Data Breach: ShinyHunters Exploit OAuth Supply Chain Attack to Steal Customer Credentials for $2M Sale

7 May 2026  |  dark6  |  Databreach

Vercel has confirmed a security breach originating through a compromised third-party AI tool (Context.ai), where attackers used stolen OAuth tokens to access internal systems and enumerate customer environment...

>> read more