<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Oauth-Abuse on CuraSec</title><link>https://curasec.metacog.co.kr/tags/oauth-abuse/</link><description>Recent content in Oauth-Abuse on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 21 Aug 2026 11:38:25 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/oauth-abuse/index.xml" rel="self" type="application/rss+xml"/><item><title>Russian Clusters Abuse Google OAuth and WhatsApp Linking to Hijack Accounts</title><link>https://curasec.metacog.co.kr/insights/2026-08-21-suspected-russian-hackers-abuse-google-oauth-and-whatsapp-li/</link><pubDate>Fri, 21 Aug 2026 11:38:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-21-suspected-russian-hackers-abuse-google-oauth-and-whatsapp-li/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Describes a novel technique where threat actors weaponize legitimate OAuth device-authorization flows and WhatsApp multi-device linking to hijack accounts without traditional phishing; no patch exists but worth reviewing whether your OAuth app consent and device-link flows have anomaly logging enabled.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Three named Russian espionage clusters are running active campaigns against academia, defense, and government targets using legitimate auth flows — build or tune detections for unusual OAuth device-code grant activity and unauthorized WhatsApp device registration events, and prioritize coverage if your org is in a targeted sector.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Nation-state espionage clusters are persistently targeting academia, aerospace/defense, government, and think tanks in the US and Europe; useful context for sector-specific threat briefings but no immediate leadership action is defined without disclosed IOCs or confirmed victim organizations.&lt;/li>
&lt;/ul></description></item><item><title>Russian Clusters UNC6293/UNC7005/UNC5976 Abuse OAuth Flows in Espionage Campaigns</title><link>https://curasec.metacog.co.kr/insights/2026-08-21-going-with-the-flow-s-distinct-clusters-target-individuals-o/</link><pubDate>Fri, 21 Aug 2026 11:38:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-21-going-with-the-flow-s-distinct-clusters-target-individuals-o/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> OAuth consent-flow abuse by APT29-linked clusters is a real attack surface for any organization using third-party OAuth integrations; audit configured OAuth app permissions and enforce stricter conditional access policies to reduce the social-engineering foothold these groups exploit.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Three active Russian clusters are running persistent campaigns against high-value sectors using OAuth flow hijacking and captive-portal redirects — pull Google&amp;rsquo;s full IOC list, hunt for anomalous OAuth token grants or device-code auth attempts since mid-2025, and tune detections for captive-portal redirect chains tied to UNC7005 TTPs documented by Reliaquest and Microsoft.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your organization falls in academia, aerospace/defense, government, or think tanks, queue a targeted user-awareness briefing on OAuth and device-code phishing before next quarter; the APT29 lineage of UNC6293 elevates this beyond routine phishing and warrants a conversation with your security team about protective intelligence coverage.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft Maps Three Salesforce OAuth Attack Paths Used by ShinyHunters</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-microsoft-maps-three-salesforce-attack-paths-tied-to-a-year/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-microsoft-maps-three-salesforce-attack-paths-tied-to-a-year/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> No platform CVE to patch — the attack surface is over-trusted OAuth connections and third-party integrations. Audit all connected apps in your Salesforce org, revoke unused OAuth grants, and review third-party vendor permissions this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Microsoft has detailed three concrete attack paths from an active, year-long campaign — hunt for anomalous OAuth authorization events and unusual connected-app activity in Salesforce audit logs going back at least 12 months to check for prior compromise.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> ShinyHunters is an active data-extortion group and this campaign abuses third-party SaaS trust, not software flaws — confirm your organization&amp;rsquo;s Salesforce OAuth integrations are inventoried, brief leadership on third-party SaaS risk exposure, and ask your Salesforce-connected vendors for attestation of their OAuth hygiene.&lt;/li>
&lt;/ul></description></item><item><title>ShinyHunters targets SaaS via OAuth abuse, vishing, and guest-access misconfig</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-defending-saas-based-applications-against-shinyhunters-oauth/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-defending-saas-based-applications-against-shinyhunters-oauth/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> ShinyHunters&amp;rsquo; TTPs — OAuth app abuse and misconfigured guest access — directly affect cloud/SaaS configurations engineers own; no KEV or exploitation signals, but audit third-party OAuth app consent grants and tighten guest-access policies in your M365/IdP tenant this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Microsoft Threat Intelligence documents an active, named campaign; review the blog for IOCs and ATT&amp;amp;CK-mappable TTPs, then hunt for anomalous OAuth token grants and vishing-preceded MFA/auth events in identity logs since the publication date.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> ShinyHunters&amp;rsquo; supply-chain and OAuth abuse pattern against SaaS platforms warrants a SaaS vendor review this quarter — confirm key vendors enforce OAuth app allowlisting and have disabled unnecessary guest access — no specific named-vendor breach requiring immediate stakeholder communication.&lt;/li>
&lt;/ul></description></item></channel></rss>