Fake OAuth client IDs are helping attackers slip past sign-in logsHelp Net Security·Jul 13, 00:00 UTC · Jul 13, 2026Data breach45
Microsoft says Russian hackers used previously identified tactic to breach senior exec emailsThe Record·Jan 26, 17:14 UTC · Jan 26, 2024Data breach157
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session TheftThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Data breach45
How to Investigate an OAuth Grant for Suspicious Activity or Overly Permissive ScopesThe Hacker News·Aug 21, 11:12 UTC · Aug 21, 2023Data breach60
Midnight Blizzard and Cloudflare-Atlassian Cybersecurity Incidents: What to KnowThe Hacker News·May 2, 03:42 UTC · May 2, 2024Data breach60
OAuth, guest accounts, and weak MFA drive SaaS riskHelp Net Security·Jul 6, 00:00 UTC · Jul 6, 2026Data breach60
Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ AttemptsThe Hacker News·Jul 21, 04:58 UTC · Jul 21, 2026Data breach145
Outlook Hack: Microsoft Reveals How a Crash Dump Led to a Major Security BreachThe Hacker News·Sep 8, 05:00 UTC · Sep 8, 2023Data breach60
Week in review: Acrobat Reader flaw exploited, Claude Mythos offensive capabilities and limitsHelp Net Security·Apr 19, 00:00 UTC · Apr 19, 2026Data breach in the wildCVE-2026-34621CVE-2026-39813CVE-2026-3980860
Microsoft Expands Cloud Logging to Counter Rising NationThe Hacker News·Jul 20, 05:24 UTC · Jul 20, 2023Data breach157
Think Your IdP or CASB Covers Shadow IT? These 5 Risks Prove OtherwiseThe Hacker News·Jun 9, 11:00 UTC · Jun 9, 2025Data breach60
What is Nudge Security and How Does it Work?The Hacker News·Dec 12, 05:43 UTC · Dec 12, 2024Data breach60
Beware the man in the cloud: How to protect against a new breed of cyberattackHelp Net Security·Jan 21, 00:00 UTC · Jan 21, 2019Data breach57
The $10 Cyber Threat Responsible for the Biggest Breaches of 2024The Hacker News·Jan 15, 00:00 UTC · Jan 15, 2025Data breach160
GitHub Says Hackers Breached Dozens of Organizations Using Stolen OAuth Access TokensThe Hacker News·May 28, 08:22 UTC · May 28, 2022Data breach45
GitHub Notifies Victims Whose Private Data Was Accessed Using OAuth TokensThe Hacker News·May 28, 08:20 UTC · May 28, 2022Data breach45
China-Linked Silk Typhoon Expands Cyber Attacks to IT Supply Chains for Initial AccessThe Hacker News·Mar 7, 04:04 UTC · Mar 7, 2025Data breach in the wildCVE-2025-0282CVE-2024-3400CVE-2023-3519+5 CVEs60
Week in review: Rail transport cybersecurity, “verified” OAuth apps used to infiltrate organizationsHelp Net Security·Feb 5, 00:00 UTC · Feb 5, 2023Data breachCVE-2022-27596CVE-2023-20076CVE-2023-22501160
Into the Breach: Breaking Down 3 SaaS App Cyber Attacks in 2022The Hacker News·Apr 7, 13:00 UTC · Apr 7, 2022Data breach60
Uncovering (and Understanding) the Hidden Risks of SaaS AppsThe Hacker News·Apr 19, 15:25 UTC · Apr 19, 2023Data breach57
Vercel Breach Tied to Context AI Hack Exposes Limited Customer CredentialsThe Hacker News·Apr 22, 15:14 UTC · Apr 22, 2026Data breach157
Week in review: Accenture data breach, great open-source cybersecurity toolsHelp Net Security·Jul 12, 00:00 UTC · Jul 12, 2026Data breach in the wildCVE-2026-48282CVE-2026-55255CVE-2026-50656160
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential RotationThe Hacker News·Jul 30, 07:40 UTC · Jul 30, 2026Data breachCVE-2026-42897CVE-2025-6637660
Product showcase: Nudge Security’s SaaS security and governance platformHelp Net Security·Mar 11, 13:18 UTC · Mar 11, 2024Data breach60
Human Error the Leading Cause of Cloud Data BreachesInfosecurity Magazine·Jul 6, 11:30 UTC · Jul 6, 2023Data breach60
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, WaterThe Hacker News·Aug 3, 14:03 UTC · Aug 3, 2026Data breachCVE-2026-42897CVE-2026-6606660
ThreatsDay Bulletin: WhatsApp Hijacks, MCP Leaks, AI Recon, React2Shell Exploit and 15 More StoriesThe Hacker News·Dec 25, 13:23 UTC · Dec 25, 2025Data breach45
Active Directory Under Siege: Why Critical Infrastructure Needs Stronger SecurityThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2025Data breach60
New MemGhost Attack Plants Persistent False Memories in AI Agents Through One EmailThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Data breachCVE-2025-32711260
Mailbox Rule Abuse Emerges as Stealthy PostInfosecurity Magazine·Apr 13, 15:00 UTC · Apr 13, 2026Data breach57
Why High Tech Companies Struggle with SaaS SecurityThe Hacker News·May 15, 00:00 UTC · May 15, 2023Data breach60
Non-Human Access is the Path of Least Resistance: A 2023 RecapThe Hacker News·Dec 15, 00:00 UTC · Dec 15, 2023Data breach57
Permiso State of Identity Security 2024: A ShakeThe Hacker News·Oct 23, 17:09 UTC · Oct 23, 2024Data breach57
Vercel attack fallout expands to more customers and thirdCyberScoop·Apr 23, 22:05 UTC · Apr 23, 2026Data breach in the wild160
GSA watchdog to 18F: Stop using SlackCyberScoop·May 13, 17:32 UTC · May 13, 2016Data breach in the wild60
Week in review: Stealth-patched FortiWeb vulnerability under active exploitation, Logitech data breachHelp Net Security·Nov 23, 00:00 UTC · Nov 23, 2025Data breach in the wildCVE-2025-13223CVE-2025-58034CVE-2025-1100160