Webinar: What happens in the first hours of a Google Workspace breach
(bleepingcomputer.com)
1.
2.
Twitch extension with 30K installs exposes users’ OAuth tokens
(bleepingcomputer.com)
3.
Webinar: How malicious OAuth apps can lead to Google Workspace breaches
(bleepingcomputer.com)
4.
Connecting every app to every other app
(news.ycombinator.com)
5.
Anthropic banned me for "suspicious signals"
(news.ycombinator.com)
6.
The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
(bleepingcomputer.com)
7.
Authorize, don't authenticate
(news.ycombinator.com)
8.
Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
(bleepingcomputer.com)
9.
Show HN: OTP Inspired actor supervisor based full stack templates
(news.ycombinator.com)
10.
11.
Hackers target Microsoft 365 accounts with 81 million login attempts
(bleepingcomputer.com)
12.
OAuth for all
(news.ycombinator.com)
13.
Cloudflare launched self-managed OAuth for all
(news.ycombinator.com)
14.
15.
Another LastPass security breach traces back to a compromised vendor
(androidauthority.com)
16.
Scope of Salesforce Attacks Expands as Icarus Leaks Data
(darkreading.com)
17.
18.
LastPass confirms data breach in Klue supply chain attack
(bleepingcomputer.com)
19.
Temporary Cloudflare accounts for AI agents
(news.ycombinator.com)
20.
Temporary Cloudflare Accounts for AI Agents
(news.ycombinator.com)
21.
Klue OAuth breach victim list grows as Icarus hackers claim attack
(bleepingcomputer.com)
22.
Zero-Touch OAuth for MCP
(news.ycombinator.com)
23.
Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks
(bleepingcomputer.com)
24.
VS Code zero-day lets hackers steal GitHub tokens in one click
(bleepingcomputer.com)
25.
Why the browser is now the front line for AI security
(bleepingcomputer.com)
26.
27.
FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
(bleepingcomputer.com)
28.
5 Steps to Managing Shadow AI Tools Without Slowing Down Employees
(bleepingcomputer.com)
29.
Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing
(bleepingcomputer.com)
30.
Composer leaks contents of tokens configured as GitHub OAuth tokens
(news.ycombinator.com)