Attackers can gain persistent software-as-a-service (SaaS) access through a single convincing consent prompt, without needing passwords or malware. Security teams have long treated multifactor ...
Proofpoint observed campaigns impersonating trusted brands like SharePoint and DocuSign with malicious OAuth applications to get into Microsoft 365 accounts. Threat actors have cooked up a clever way ...
Organizations often create guest accounts to give contractors, suppliers, and partners temporary access to files and SaaS applications. Many of these accounts remain active long after they are needed, ...
A sharp rise in OAuth device code phishing campaigns designed to exploit Microsoft 365 and other cloud platforms is forcing security leaders to re-think enterprise trust. Account takeover is no longer ...
A new phishing-as-a-service (PhaaS) platform called Kali365 is being distributed in the wild, primarily via Telegram, the FBI has warned. First detected in April 2026, Kali365 provides cyber threat ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results