OAuth & SaaS tokens
OAuth token abuse, connected-app compromise, and the identity layer behind SaaS integrations.
Malware can use Windows Hello keys to sign into Entra ID as you
Malware in a signed-in Windows session can use the Windows Hello key to log into Microsoft Entra ID and hold a 90-day token. How to detect and mitigate it.
Device-code phishing jumped 1,500% in 2026: attackers take over Microsoft 365 accounts with no password or MFA
Device-code phishing rose 1,500% in 2026, letting attackers mint Microsoft 365 tokens with no password or MFA. Here is how to detect and block the OAuth flow.
HollowGraph turns Microsoft 365 into a C2 channel with no patch
HollowGraph runs its command channel through a hijacked Microsoft 365 calendar over the Graph API. No CVE, no patch: here is how to detect it.
RabbitMQ's takeover flaw is conditional. The quiet one isn't.
RabbitMQ patched CVE-2026-57219 and CVE-2026-57221. The severe OAuth secret leak needs OAuth configured; the quiet metadata bug hits every shared virtual host.
This login library let a stranger sign in as you with just your email
CVE-2026-49757 (CVSS 9.2) let attackers take over accounts in Elixir apps built on ash_authentication by matching users on email instead of identity.
Your Salesforce wasn't breached. A connected app handed over the data.
The Icarus group stole Salesforce CRM data through Klue's connected app, not a Salesforce flaw. Why OAuth integration tokens are the unmonitored attack surface.
Ready to meet the Guardians?
Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.