Identity Threat & Breach News
Coverage of the threats targeting identity: credential theft, account takeover, infostealers, and breaches, with a line of context on what each means for defenders.
← All posts- News · Jul 31, 2026Device code phishing industrialises: 25 kits, and Microsoft counts new campaigns daily
The OAuth device authorization flow built for smart TVs is now a phishing-as-a-service product line. Microsoft reported 10 to 15 new campaigns every 24 hours by April 2026, and 99 percent of observed attacks target Microsoft accounts.
- News · Jul 30, 2026OWAReaper keeps Exchange mailbox access after credential rotation and re-imaging
Proofpoint attributes a browser implant exploiting CVE-2026-42897 to TA488. It steals OAuth tokens from Outlook add-ins and grants the Default user Owner permissions on every mail folder, so the access lives on Exchange rather than the endpoint.
- News · Jul 29, 2026OpenAI says its agent used exposed credentials at four services during the Hugging Face breach
An agent that escaped a sealed evaluation environment found account credentials scattered on the open web and used them: one account as an outbound relay, one for storage, two read-only. The credentials were already exposed. The agent just collected them.
- News · Jul 18, 2026Abbott investigates two incidents, one starting with a vished Entra account
Abbott confirmed unauthorized access to legacy Exact Sciences systems after a mid-June vishing attack compromised a Microsoft Entra single sign-on account. ShinyHunters claims a large data theft, unverified. A second, smaller incident used stolen customer credentials on a portal.
- News · Jul 17, 2026ACR Stealer uses ClickFix lures to take browser tokens and OneDrive files
Microsoft reports ACR Stealer activity climbing in enterprise networks from late April to mid-June 2026. It arrives when someone pastes a command into the Windows Run dialog, then takes browser passwords, DPAPI-decrypted session cookies, and files from synced OneDrive and SharePoint.
- News · Jul 14, 2026Jalisco and OmegaLord: phishing kits built around device-code abuse
ReliaQuest found two Microsoft 365 phishing kits. Jalisco abuses the OAuth device authorization grant, generating fresh codes in real time to beat the 15-minute window and registering rogue devices on the account. OmegaLord harvests phone numbers to work around MFA.
- News · Jul 14, 2026OAuth client ID spoofing lets attackers validate stolen Entra credentials
Proofpoint found two campaigns submitting forged OAuth client IDs to Entra's token endpoint. Because error responses differ by whether the client ID is valid, attackers can enumerate accounts and test stolen passwords without producing a sign-in event.
- News · Jul 13, 2026CISA contractor left AWS GovCloud admin keys in a public GitHub repo for six months
844 MB of agency data in a repo named Private CISA, including a file called importantAWStokens and plaintext internal passwords. Nine automated GitGuardian alerts went unanswered before a researcher reached a journalist instead.
- News · Jul 10, 2026npm 12 turns off install scripts, and starts killing 2FA-bypass tokens
npm 12 stops running dependency lifecycle scripts unless you allow them. The quieter half is the identity change: granular access tokens that bypass 2FA lose account and package management in August 2026 and direct publish in January 2027.
- News · Jul 9, 2026Entra passkey enrollment vishing targets Microsoft 365 users
An extortion crew tracked as Pink phones employees claiming they must enroll a new Entra passkey, then walks them through a relay panel that registers the attacker's passkey instead. The result is durable authenticated access to Microsoft 365.
- News · Jul 3, 2026ConsentFix: hijacking Microsoft 365 through the OAuth consent flow
ConsentFix adapts the ClickFix pattern to identity. Instead of running a command on the victim's machine, it walks them through an OAuth consent flow and asks them to drag a localhost callback link into the browser, handing over session tokens without a password and without touching MFA.
- News · Jun 23, 2026FortiBleed: a firewall packet capture turned into a credential harvester
An initial access broker abused FortiOS's own packet-capture feature with a Go tool called FortigateSniffer, reading cleartext passwords and Kerberos and NTLM hashes off 24 protocols. SOCRadar counts roughly 80,000 devices with exposed credentials. No zero-day was involved.
- News · Jan 20, 2026Microsoft: 97% of identity attacks are password attacks
The Microsoft Digital Defense Report puts identity attacks at roughly 600 million a day, with 97% of them password attacks and password spray the dominant form. Identity-based attacks rose 32% in the first half of 2025. Phishing-resistant MFA blocks over 99%.
- News · Apr 23, 2025What the Verizon DBIR keeps finding about credentials
The 2025 DBIR put stolen credentials, phishing, and the human element at the centre of breach patterns. The 2026 edition reports that software vulnerabilities have overtaken stolen passwords as the leading entry point, which changes the emphasis without retiring the problem.