F5 issued patches for a critical zero-day in its BIG-IP Access Policy Manager, tracked as CVE-2026-94127, which is being exploited to achieve remote code execution on systems configured as an OAuth Authorization Server. F5 says setups using APM only as an OAuth Client or Resource Server are unaffected, and offered an iRule-based mitigation for those unable to patch immediately. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and directed federal agencies to remediate it by Friday.
bleepingcomputer.com
· 2026-09-23
French security firm CrowdSec disclosed that attackers used the Shai-Hulud worm to compromise a former employee's machine in May, stealing a GitHub OAuth token that still had read access to the company's private repositories. Over roughly nine minutes, attackers downloaded about 170 private repos plus 130+ public ones; CrowdSec only learned of the breach on September 16 after stolen source code surfaced on the cybercrime marketplace pwnforum.
darkreading.com
· 2026-09-22
BleepingComputer is partnering with Material Security for a live webinar on September 23 examining documented Google Workspace breaches. Speakers Rajan Kapoor of Material Security and Rick Fitzgerald of Fireside Consulting will dissect two incidents where attackers used social engineering and rogue OAuth apps to gain access, then walk through the response decisions that followed.
bleepingcomputer.com
· 2026-09-22
Security researchers warn that attackers can gain lasting access to SaaS and cloud accounts simply by tricking a logged-in user into approving a malicious OAuth application, sidestepping passwords, malware, and multifactor authentication entirely. Once granted, these app permissions can let attackers read email, browse files, pull source code, or touch CI/CD systems through legitimate API access until the tokens or grants are revoked.
darkreading.com
· 2026-09-18
BleepingComputer and Material Security are hosting a live webinar on September 23, 2026, examining real, publicly documented breaches of Google Workspace environments. Speakers Rajan Kapoor of Material Security and Rick Fitzgerald of Fireside Consulting LLC will dissect incidents involving social engineering and malicious OAuth apps to identify which defenses failed and which security controls actually matter.
bleepingcomputer.com
· 2026-09-18
Scry is a new search-over-the-web service built for AI agents, exposed through the Model Context Protocol as well as a direct HTTP API. Developers connect tools like Claude Code, Codex, or Cursor to a single MCP endpoint, authenticate via OAuth or an API key, and query a rolling crawl of high-information web pages using a SQL-like interface. The service also introduces congestion-based pricing tied to usage load.
scry.io
· 2026-09-17
BleepingComputer is hosting a live webinar on September 23, 2026, featuring Material Security's Rajan Kapoor and Fireside Consulting's Rick Fitzgerald, who will dissect real, publicly documented Google Workspace breaches. The session focuses on the critical early hours after a breach is discovered, including cases where attackers used social engineering paired with malicious OAuth apps to gain entry.
bleepingcomputer.com
· 2026-09-16
Security firm Socket found that the Chrome and Firefox extension 'Twitch Enhanced Viewer | JeetBot,' which promises ad-blocking and forced 1080p playback, secretly captures users' Twitch OAuth session tokens. The credentials are routed through proxy servers run by JeetBot, a Russian-language streaming and chatbot service, where they land in plaintext request logs accessible to the vendor. The extension exempts ten hardcoded Russian-language channels from this behavior, and its own store listing admits earlier versions sent tokens to its servers outright.
bleepingcomputer.com
· 2026-09-14
BleepingComputer is hosting a live webinar on September 23, 2026, with Material Security's Rajan Kapoor and Fireside Consulting's Rick Fitzgerald, who will dissect two real breaches of Google Workspace environments carried out through malicious OAuth applications and social engineering rather than stolen passwords. The session will walk through how the attacks unfolded, the security gaps that let them succeed, and the response decisions made in the early hours of each incident.
bleepingcomputer.com
· 2026-09-14
Val Town, a vibe coding platform, describes how it adopted Dynamic Client Registration (DCR), a little-known OAuth extension built into the MCP spec by Anthropic and OpenAI, to let apps automatically register as OAuth clients without manual developer portal work. Using this, Val Town built its MCP server so Claude and ChatGPT can authenticate into user accounts, and created a library called std/oauth that lets any app add 'Login with Val Town' in just two lines of code.
blog.val.town
· 2026-09-04
A long-time paying Anthropic customer on the $200/month Claude Max plan reports abrupt account termination via a form email citing 'suspicious signals' tied to a Usage Policy violation, with no specific reason given. The user says another Max subscriber elsewhere was banned right after paying, and the only appeal route is an automated in-product form rather than contact with a person.
kix.codes
· 2026-09-02