Threat Intelligence
ConsentFix v3 Runs on Cloudflare, Dropbox, and ZoomInfo
The OAuth phishing kit is plumbed end-to-end through legitimate SaaS, which is exactly the point.
OAuth Abuse focuses on the exploitation of token-based authentication and delegated authorization frameworks. As organizations increasingly rely on SaaS integrations, threat actors have pivoted from stealing passwords to hijacking active sessions and abusing "read-write" scopes. This tag tracks technical signatures of token theft, malicious app integrations, and the critical failure of over-permissioned third-party ecosystems.
Threat Intelligence
The OAuth phishing kit is plumbed end-to-end through legitimate SaaS, which is exactly the point.
Data Breaches
New forensic details reveal that the massive data exfiltration at Vercel began with a single employee downloading a compromised Roblox game cheat, highlighting the catastrophic intersection of personal device use and enterprise SaaS permissions. SAN FRANCISCO, CA — The security community is processing the full scope of the breach involving Vercel