{"id":55191,"date":"2024-01-29T14:58:55","date_gmt":"2024-01-29T14:58:55","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/35459\/Microsoft-Fell-Victim-To-OAuth-Attack-It-Issued-Warning-About.html"},"modified":"2024-01-29T14:58:55","modified_gmt":"2024-01-29T14:58:55","slug":"microsoft-fell-victim-to-oauth-attack-it-issued-warning-about","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\/","title":{"rendered":"Microsoft Fell Victim To OAuth Attack It Issued Warning About"},"content":{"rendered":"<div><img decoding=\"async\" src=\"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2024\/01\/credential-microsoft-password.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Microsoft disclosed it was also victimized by cyberespionage criminals who abused OAuth applications to access protected corporate accounts. The tech giant had previously warned of ongoing attacks by advanced persistent threat group with ties to Russia.<\/p>\n<p>Now Microsoft has revealed some of the technical details and the extent of the attack against its own implementation of the OAuth credential management platform in an effort to help other organizations &#8220;protect, detect, and respond to similar threats.&#8221;<\/p>\n<p>In a Jan. 25 post, <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/01\/25\/midnight-blizzard-guidance-for-responders-on-nation-state-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">elaborating on the OAuth attacks against its own senior executives<\/a>, Microsoft\u2019s threat intelligence team said APT29 (aka Cozy Bear, Midnight Blizzard or Nobelium) attackers were adept at abusing apps that used the popular OAuth token-based authentication and authorizations open standard.<\/p>\n<p>&#8220;Microsoft was able to identify these attacks in log data by reviewing&nbsp;Exchange Web Services (EWS) activity and using our audit logging features, combined with our extensive knowledge of Midnight Blizzard,&#8221; according to last week&#8217;s post.<\/p>\n<p>Hackers initially breached a Microsoft test tenant account and a legacy test OAuth application. That application had elevated access to Microsoft\u2019s corporate environment and allowed adversaries to create additional malicious OAuth applications.<\/p>\n<p>\u201cThey created a new user account to grant consent in the Microsoft corporate environment to the actor controlled malicious OAuth applications,\u201d the company said in its Jan. 25 post.<\/p>\n<p>\u201cThe threat actor then used the legacy test OAuth application to grant them the Office 365 Exchange Online &#8216;full_access_as_app role&#8217;, which allows access to mailboxes,&#8221; researchers wrote.<\/p>\n<h2>Hardening your OAuth attack surface<\/h2>\n<p>Hiding its tracks was core to Midnight Blizzard or APT29&#8217;s ongoing success.<\/p>\n<p>&#8220;As part of their multiple attempts to obfuscate the source of their attack, Midnight Blizzard used residential proxy networks, routing their traffic through a vast number of IP addresses that are also used by legitimate users, to interact with the compromised tenant and, subsequently, with Exchange Online,&#8221; researchers wrote.<\/p>\n<p>The abuse of residential proxies isn&#8217;t new by adversaries, Microsoft points out. It&#8217;s a technique that &#8220;makes traditional indicators of compromise (IOC)-based detection infeasible due to the high changeover rate of IP addresses,&#8221; researchers said.<\/p>\n<p>&#8220;Residential proxies&nbsp;allow you to choose a specific&nbsp;location&nbsp;(country, city, or mobile carrier) and surf the web as a real user in that area,&#8221; according to John McHenry, data analyst and founder of Proxyplus.cz. In a <a href=\"https:\/\/brightdata.com\/blog\/guest-post\/what-is-a-residential-proxy#\">Bright &nbsp;Proxies definition<\/a>, McHenry explains that these types of proxies &#8220;can be defined as intermediaries that protect users from general web traffic. They act as buffers while also concealing your IP address.&nbsp;Proxies are alternative IP addresses assigned to users by the provider.&#8221;<\/p>\n<p>Microsoft said &#8220;due to the heavy use of proxy infrastructure with a high changeover rate, searching for traditional IOCs, such as infrastructure IP addresses, is not sufficient to detect this type of Midnight Blizzard activity.&#8221;<\/p>\n<p>Microsoft recommends a number of auditing and detection techniques to mitigate this type of &nbsp;OAuth-based attacks. They include:<\/p>\n<h2>Previous warnings of OAuth attacks<\/h2>\n<p>In a Dec. 12 post last year, Microsoft Threat Intelligence warned malicious actors were <a href=\"https:\/\/www.scmagazine.com\/news\/threat-actors-launch-financially-motivated-attacks-abusing-oauth-applications\" target=\"_blank\" rel=\"noreferrer noopener\">abusing OAuth apps to carry out financially motivated attacks<\/a>. Microsoft warned threat actors were using password spray-and-pray style attacks to compromise a legacy, non-production test tenant account that did not have multifactor authentication (MFA) enabled.<\/p>\n<p>Next, in a technical post published earlier this <a href=\"https:\/\/www.scmagazine.com\/news\/microsoft-reveals-in-sec-filing-that-executive-emails-breached-by-russian-apt\">month Microsoft upped its warnings<\/a> and attributed attacks to APT29 stating the group was targeting OAuth applications to hack into executive accounts. At the time, Microsoft revealed hackers stole emails from members of its own senior leadership team, along with employees with roles in cybersecurity, legal, and other parts of the organization.<\/p>\n<p>Microsoft said the breached accounts were discovered on Jan. 12.<\/p>\n<h2>Coincidence or victim?<\/h2>\n<p>In its Jan. 25 post, Microsoft&#8217;s threat intelligence team said the information gained from the investigation into APT29\u2019s attack on Microsoft identified the gang had also targeted other organizations, who it did not name.<\/p>\n<p>Hewlett Packard Enterprise (HPE) disclosed last week its Microsoft 365 email environment was <a href=\"https:\/\/www.scmagazine.com\/news\/apt-lurked-in-hpes-systems-for-over-6-months\" target=\"_blank\" rel=\"noreferrer noopener\">infiltrated by APT29 last year<\/a>. HPE did not explain how the breach occurred and it is not known whether the attack was one of those the Microsoft researchers were referring to in their post.<\/p>\n<p>HPE said it \u201cwas notified\u201d of the breach on Dec. 12 (the same Microsoft published its OAuth post) but when asked by media who the notification came from, it declined to say.<\/p>\n<p>Security researcher and former Microsoft employee Kevin Beaumont <a href=\"https:\/\/www.linkedin.com\/posts\/kevin-beaumont-security_in-major-gaffe-hacked-microsoft-test-account-activity-7157460621779738624-_OkA?utm_source=share&amp;utm_medium=member_desktop\" target=\"_blank\" rel=\"noreferrer noopener\">said in a LinkedIn post<\/a> he expected organizations would continue to suffer Microsoft 365 breaches. While there were \u201ca whole range of strategic things MS need to do to uplift security,\u201d he believed they could be achieved.<\/p>\n<p>\u201cI\u2019m actually really confident Microsoft can get on top of this and do the right things, and it\u2019s an exciting time for them as they can spend a few years changing course to get their own house in order,\u201d Beaumont said. \u201cIf they do, society will benefit as it will flow to things like less ransomware incidents elsewhere too. If they don\u2019t, it\u2019s a dark path.\u201d<\/p>\n<p>\u201cImplementing security practices that strengthen account credentials such as enabling MFA reduces the chance of attack dramatically,\u201d the researchers said.<\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/35459\/Microsoft-Fell-Victim-To-OAuth-Attack-It-Issued-Warning-About.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":55192,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[277],"tags":[10833],"class_list":["post-55191","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-blogs","tag-headlinehackermicrosoftemailrussiadata-losspassword"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Microsoft Fell Victim To OAuth Attack It Issued Warning About 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Microsoft Fell Victim To OAuth Attack It Issued Warning About 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2024-01-29T14:58:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2024\/01\/credential-microsoft-password.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Microsoft Fell Victim To OAuth Attack It Issued Warning About\",\"datePublished\":\"2024-01-29T14:58:55+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\\\/\"},\"wordCount\":877,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about.jpg\",\"keywords\":[\"headline,hacker,microsoft,email,russia,data loss,password\"],\"articleSection\":[\"CyberSecurity Blogs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\\\/\",\"name\":\"Microsoft Fell Victim To OAuth Attack It Issued Warning About 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about.jpg\",\"datePublished\":\"2024-01-29T14:58:55+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about.jpg\",\"width\":800,\"height\":533},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,microsoft,email,russia,data loss,password\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackermicrosoftemailrussiadata-losspassword\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Microsoft Fell Victim To OAuth Attack It Issued Warning About\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Microsoft Fell Victim To OAuth Attack It Issued Warning About 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\/","og_locale":"en_US","og_type":"article","og_title":"Microsoft Fell Victim To OAuth Attack It Issued Warning About 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2024-01-29T14:58:55+00:00","og_image":[{"url":"https:\/\/files.scmagazine.com\/wp-content\/uploads\/2024\/01\/credential-microsoft-password.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Microsoft Fell Victim To OAuth Attack It Issued Warning About","datePublished":"2024-01-29T14:58:55+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\/"},"wordCount":877,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/01\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about.jpg","keywords":["headline,hacker,microsoft,email,russia,data loss,password"],"articleSection":["CyberSecurity Blogs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\/","url":"https:\/\/www.threatshub.org\/blog\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\/","name":"Microsoft Fell Victim To OAuth Attack It Issued Warning About 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/01\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about.jpg","datePublished":"2024-01-29T14:58:55+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/01\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/01\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about.jpg","width":800,"height":533},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/microsoft-fell-victim-to-oauth-attack-it-issued-warning-about\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,microsoft,email,russia,data loss,password","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackermicrosoftemailrussiadata-losspassword\/"},{"@type":"ListItem","position":3,"name":"Microsoft Fell Victim To OAuth Attack It Issued Warning About"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/55191","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=55191"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/55191\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/55192"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=55191"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=55191"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=55191"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}