Entity

OAuth

OAuth is an open standard authorization protocol that allows users to grant third-party applications access to their resources on another service without sharing their credentials.

Why it’s in the news: It is in the news due to widespread security vulnerabilities, including consent abuse, token theft, and client ID spoofing, which are being exploited by malicious actors.

Latest on OAuth

  • MFA Won't Save You From OAuth Consent Abuse
  • Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens
  • Russian snoops add OAuth abuse to targeted phishing campaigns
  • 4 million fake applications and one blind spot: A SOC playbook for OAuth client ID spoofing
  • RabbitMQ flaws expose OAuth secrets, risk complete takeover of the broker
  • Novel OAuth Client ID Spoofing Technique Targets Cloud Environments

Connections

5 entities linked to OAuth across the news graph.

Also connected to (5)