<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Oauth on CuraSec</title><link>https://curasec.metacog.co.kr/tags/oauth/</link><description>Recent content in Oauth on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 05 Aug 2026 13:01:27 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/oauth/index.xml" rel="self" type="application/rss+xml"/><item><title>Greatness PhaaS Adds Device Code Phishing to Bypass MFA</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-greatness-phaas-adds-device-code-phishing-to-bypass-mfa-and/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Device code flow abuse bypasses MFA by design; audit your identity provider (Entra ID, Okta) and restrict or disable the OAuth Device Authorization Grant for users/apps that don&amp;rsquo;t require it — block or conditional-policy-gate this flow this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No IOCs provided, but Greatness PhaaS commoditizing device code phishing signals growing campaign volume; build detections in Entra/Okta logs for unexpected device code authorization requests, particularly outside normal device-enrollment windows.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> MFA bypass techniques are now packaged in commercial crimeware toolkits, eroding the assurance value of standard MFA — useful context for risk register updates and for evaluating phishing-resistant auth (FIDO2/passkeys) as a strategic control.&lt;/li>
&lt;/ul></description></item><item><title>OAuth Client ID Spoofing Bypasses Entra ID Sign-In Telemetry</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-oauth-client-id-spoofing-lets-attackers-validate-stolen-micr/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-oauth-client-id-spoofing-lets-attackers-validate-stolen-micr/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> At least two active threat actors are exploiting this Entra ID gap, but there&amp;rsquo;s no patch—the exposure is architectural. Audit your Entra OAuth app registrations and conditional access policies, and restrict which OAuth clients are permitted for interactive and non-interactive flows.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> This technique deliberately suppresses successful sign-in events, creating a blind spot in standard Entra telemetry; shift detection to Entra audit logs for anomalous OAuth client IDs and non-standard token-request patterns, and run a retrospective hunt across the past 90 days of OAuth activity.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Credential-validation activity against your Entra tenant may be occurring without triggering existing alerts; ask your security team to assess current detection coverage for OAuth-based evasion and confirm whether identity monitoring logs are capturing the necessary audit events.&lt;/li>
&lt;/ul></description></item><item><title>RabbitMQ Flaws Could Leak OAuth Secrets, Break Tenant Isolation</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-rabbitmq-flaws-could-leak-oauth-secrets-and-expose-cross-ten/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-rabbitmq-flaws-could-leak-oauth-secrets-and-expose-cross-ten/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> RabbitMQ is widely deployed as enterprise messaging infrastructure; these access control flaws — OAuth client secret leakage and cross-tenant queue metadata exposure — represent real risk for teams running it in multi-tenant or OAuth-integrated configurations. No active exploitation or PoC reported, but identify affected versions and schedule patching once a fix is available.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, no reported exploitation, and no actionable detection surface in this disclosure; file for context in case RabbitMQ compromise indicators surface later, but no hunt or detection work is warranted now.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>