logo

Microsoft Previews Feature to Block Malicious OAuth Apps

ID: 6fd440e2-51b8-58d7-bd2d-a98371cc1064

STIX ID: report--6fd440e2-51b8-58d7-bd2d-a98371cc1064

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-05-06

Date Updated: 2026-04-21

Author: Jeffrey Schwartz, Contributing Writer

...
...

The report explains that attackers are increasingly abusing malicious OAuth apps to gain persistent access to cloud accounts and launch phishing, credential-stuffing, and spam campaigns; Microsoft observed such attacks and Dropbox warned of exposed API/OAuth credentials. In response, Microsoft is previewing Defender XDR capabilities that automatically disable compromised OAuth apps to disrupt these attacks and has added OT/ICS protections and AI-assisted disruption to speed detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.