Application Security Claude Code OAuth Tokens Can Be Stolen Through Stealthy MCP Hijacking Mitiga researchers say attackers can silently redirect Claude Code MCP traffic, intercept OAuth tokens, and maintain persistent access to connected SaaS platforms. Kevin TownsendMay 7, 2026
Artificial Intelligence Shadow AI Risk: How SaaS Apps Are Quietly Enabling Massive Breaches From Chaos to Control examines the chaos that often comes from shadow AI hidden in SaaS apps and urges better visibility and control over... Kevin TownsendMarch 18, 2026
Email Security Legacy Google Service Abused in Phishing Attacks A sophisticated phishing campaign abuses weakness in Google Sites to spoof Google no-reply addresses and bypass protections. Ionut ArghireApril 22, 2025
Email Security Google OAuth Flaw Leads to Account Takeover When Domain Ownership Changes A vulnerability in Google’s OAuth implementation allows takeover of old employee accounts when domain ownership changes. Ionut ArghireJanuary 15, 2025
Application Security Millions of Websites Susceptible to XSS Attack via OAuth Implementation Flaw Researchers discovered and published details of an XSS attack that could potentially impact millions of websites around the world. Kevin TownsendJuly 29, 2024
Cloud Security Researchers Flag Account Takeover Flaw in Microsoft Azure AD OAuth Apps Businesses using ‘Log in with Microsoft’ could be exposed to privilege escalation and full account takeover exploits. Ryan NaraineJune 20, 2023
Vulnerabilities OAuth Vulnerabilities in Widely Used Expo Framework Allowed Account Takeovers OAuth vulnerabilities found in the widely used Expo application development platform could have been exploited for account takeovers. Eduard KovacsMay 24, 2023