ZeroHour

Search: “OneDrive”

2 stories in the last 24h

ZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability

ZDI disclosed an unpatched SSRF information disclosure flaw (CVE-2026-92204, CVSS 7.7) in Airbyte's OneDrive connector, requiring authentication.

ZDI-26-704 describes a server-side request forgery vulnerability in the _get_shared_drive_object function of Airbyte's OneDrive connector. Remote authenticated attackers can initiate arbitrary server-side requests leading to information disclosure. The flaw scores CVSS 7.7, is tracked as CVE-2026-92204, and is published as a 0day advisory without a referenced fix.

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

N0va phishkit targets US and EU organizations with trusted-brand lures, capturing tokens via legitimate authentication flows to gain SSO access to corporate resources.

The N0va phishing kit targets organizations in government, technology, consulting, and healthcare across North America and Europe with lures impersonating Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign. Victims are guided through legitimate authentication flows, including device code phishing, after which N0va captures access and refresh tokens and abuses token-exchange or device-registration mechanisms to establish SSO access. ANY.RUN tracks the campaign via a characteristic /api/verification/init URL pattern and demonstrates detection in its interactive sandbox.

The Hacker Newsupdated · 2h agofirst · 5h agoPhishing & fraud in the wild 9 sources