logo

OAuth Attacks Target Microsoft 365, GitHub

ID: b359a006-8002-5d0a-bcc6-376a4320a8c6

STIX ID: report--b359a006-8002-5d0a-bcc6-376a4320a8c6

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-03-17

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Multiple active campaigns are abusing malicious OAuth applications — impersonating Adobe Acrobat/Drive, DocuSign, and fake GitHub security alerts — to redirect users to credential-phishing pages or to obtain full repository access; attackers request seemingly limited permissions to evade detection and enable account takeover, targeting organizations in healthcare, supply chain, retail, government across the US and Europe and more than 8,000 GitHub repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.