logo

OAuth Phishing, Foreign Router Risks, and the Rise of Identity-Based Cyber Attacks

ID: 1fd6d147-556a-51a9-b7a6-8698b9e6c971

STIX ID: report--1fd6d147-556a-51a9-b7a6-8698b9e6c971

Feed Name: WatchGuard Secplicity Blog

Threat Score
70/100

Date Published: 2026-04-01

Date Updated: 2026-05-01

Author: The Editor

...
...

The report highlights a broad shift in attacker behavior toward exploiting trusted workflows and identity controls rather than traditional perimeter breaches: specifically calling out a phishing campaign that abuses OAuth device authentication flows to bypass MFA and obtain persistent tokens, concerns about supply-chain risk in network hardware, and data showing identity-based attacks and misconfigurations as primary initial access vectors. It recommends auditing device/application access, restricting device authentication flows, strengthening identity as a control plane, and improving patching and configuration hygiene to align defenses with how attacks occur today.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.