Hackers Abused Microsoft’s “Verified Publisher” OAuth Apps to Hack Corporate Email Accounts

[![Microsoft OAuth Apps hacking](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=)]() Microsoft on Tuesday said it took steps to disab ...

Continue Reading
Microsoft Investigation – Threat actor consent phishing campaign abusing the verified publisher process

Summary On December 15th, 2022, Microsoft became aware of a consent phishing campaign involving threat actors fraudulently impersonating legitimate companies when enrolling in the Microsoft Cloud Part ...

Continue Reading
Cross-site request forgery vulnerability in Jenkins Bitbucket OAuth Plugin

A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account.Read More ...

Continue Reading
Session fixation vulnerability in Jenkins Bitbucket OAuth Plugin

Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.Read More ...

Continue Reading
Session fixation vulnerability in Jenkins Bitbucket OAuth Plugin

Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.Read More ...

Continue Reading
Cross-site request forgery vulnerability in Jenkins Bitbucket OAuth Plugin

A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account.Read More ...

Continue Reading
CVE-2023-24428

A cross-site request forgery (CSRF) vulnerability in Jenkins Bitbucket OAuth Plugin 0.12 and earlier allows attackers to trick users into logging in to the attacker's account.Read More ...

Continue Reading
CVE-2023-24427

Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: