OAuth abuse emerges as Workspace breach path
A webinar will examine two attacks that used malicious OAuth apps and social engineering to breach Google Workspace environments.
30 results for “soc”
A webinar will examine two attacks that used malicious OAuth apps and social engineering to breach Google Workspace environments.
A cross-store Twitch extension sent OAuth tokens for roughly 31,000 users to operator proxies, Socket reports.
A fintech breach via fake government emails exposes sensitive customer data, raising questions about verification controls.
Microsoft ties passkey-themed social engineering to extortion gangs that blend into Microsoft 365 traffic to steal files and email.
ClickFix attacks have spread from exotic to mainstream, infecting Windows and macOS users via fake CAPTCHAs and terminal commands.
Young scammers' lavish purchases led FBI to suspects in $240M bitcoin theft.
Defense contracts in LA County doubled in 10 years as startups and venture capital reshape aerospace.
A phishing campaign spanning 46 countries uses fake documents to push RMM tools, with 45% of activity aimed at the US.
Can SOC 2 compliance and a subscription model differentiate Ollie in a crowded AI assistant market?
Citizen Lab finds NSO Group spyware on an activist's iPhone via a zero-click exploit, highlighting ongoing surveillance of Serbian civil society.
Attackers buy legitimate Chrome, Edge extensions and push malware via updates, Socket reports.
Microsoft warns of TerminalFix ClickFix variant that tricks users into running malicious PowerShell commands via fake Cloudflare checks.
A weekly roundup: 296K-device botnet, 100+ water systems targeted, and a SharePoint RCE chain.
Meta settles teen-harm suit for $18B, promising sweeping Instagram and Facebook changes that may prove nearly impossible to enforce.
LACMA's 2025 breach exposed social security and medical data; notifications sent.
Attackers shift focus from login to onboarding and account recovery, exploiting weak identity verification.
ReliaQuest says ShinyHunters accessed an identity dashboard briefly but no customer data was compromised.
Wazuh adds AI-powered analyst tools and integrations to ease security operations workload.
TikTok is developing a feature to let users send money via DMs, code hidden in its iPhone app suggests, according to a Bloomberg report.
Reddit begins testing a new audio and video experience for select posts, similar to TikTok-style narrated stories.
UNISOC modem flaw lets attackers escalate code execution to kernel level via video calls.
A two-stage exploit chain can achieve full Android kernel access on Unisoc devices via VoLTE video call, with no patch.
SOCRadar says most orgs hit in LiteLLM attack were earlier Trivy victims, not LiteLLM.
A new Mirai-based Linux botnet uses encrypted C2, SOCKS proxies, and exploits in routers to hijack edge devices.
Researchers have uncovered a new macOS infostealer that uses ClickFix social engineering and has stealthy remote browser control capabilities.
Bluesky's new CEO and COO will argue open protocols can reboot social media at TechCrunch Disrupt 2026.
Hundreds of malicious Chrome extensions impersonate VPNs, routing user traffic through a proxy.
Microsoft's August Patch Tuesday fixes 421 CVEs, including one exploited zero-day and two publicly disclosed flaws.
Appeals court denies platforms' Section 230 bid, allowing thousands of addiction lawsuits to proceed.
Levi Strauss investigates a breach after attackers used social engineering to access employee PCs and exfiltrate corporate data.