Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

Tag

#OAuth

8 articles covering OAuth across campaign analysis, detection engineering, and defender tradecraft.

Coverage

8 entries

Field Analysis

Dual UseInfrastructure IntelligenceMay 31, 20268 min read

Kali365 and the Productization of Token Theft

An FBI-flagged phishing-as-a-service kit rents Microsoft 365 token theft for $250 a month, packaging device-code and OAuth abuse into a point-and-click dashboard that defeats MFA without a fake login page.

Read more:FBI IC3Malwarebytes

By PhishPond Desk

  • #Infrastructure Intelligence
  • #Phishing-as-a-Service
  • #Microsoft 365

Field Analysis

Blue TeamDetection & ValidationMay 6, 20268 min read

Detect OAuth Abuse by Watching What Apps Do After Consent

A static permission review cannot catch a trusted integration whose token is later stolen or whose behavior changes.

Read more:The Hacker NewsMicrosoft Learn

By PhishPond Desk

  • #OAuth
  • #Detection Engineering
  • #API Security

Field Analysis

Blue TeamDetection & ValidationMay 6, 20267 min read

OAuth Consent Governance Needs a Front Door and a Cleanup Crew

Restricting new consent is only half the work. Existing app grants need review, ownership, and a path to removal when risk changes.

Read more:Microsoft LearnMicrosoft Learn

By PhishPond Desk

  • #OAuth
  • #Microsoft Entra
  • #Google Workspace

Field Analysis

Blue TeamDetection & ValidationMay 6, 20269 min read

The Drift Token Lesson Is SaaS Blast Radius, Not Just Vendor Risk

The Salesloft Drift incident showed how a trusted integration token can become an access path into customer SaaS data without a fresh user login.

Read more:The Hacker NewsThe Hacker News

By PhishPond Desk

  • #OAuth
  • #Supply Chain
  • #Salesforce

Field Analysis

Blue TeamDetection & ValidationMay 6, 20268 min read

Unmanaged OAuth Grants Are the SaaS Back Door Hiding in Plain Sight

Persistent OAuth grants let third-party apps keep operating after the original login, password reset, or employee lifecycle event has faded from view.

Read more:The Hacker NewsMicrosoft Learn

By PhishPond Desk

  • #OAuth
  • #SaaS Security
  • #Credential Theft

Field Analysis

Blue TeamTradecraft LabsMay 1, 202611 min read

Device Code Phishing: A Walkthrough and Detection Playbook

Device code phishing turns a legitimate OAuth flow into a credential-free token theft technique. Here is how it runs end-to-end and what defenders can hunt on in Sentinel and Defender XDR.

Read more:Microsoft Security BlogIETF

By PhishPond Desk

  • #Device Code
  • #OAuth
  • #Identity

Field Analysis

Red TeamCampaign AnalysisApr 24, 20269 min read

Approval Fatigue Becomes the New Credential Theft Front Door

Attackers are blending push prompts, urgent collaboration lures, and identity fatigue to move users from suspicion to accidental approval.

Read more:The Hacker NewsThe Hacker News

By PhishPond Desk

  • #Push Fraud
  • #OAuth
  • #Identity

Field Analysis

Blue TeamResearch ReportsApr 22, 202610 min read

Research Note: OAuth Consent Debt Builds Quietly Until Incident Response Needs It Gone

OAuth app grants accumulate over time, and stale consent can become a hidden access path when vendors, users, or integrations are later compromised.

Read more:Microsoft LearnThe Hacker News

By PhishPond Desk

  • #OAuth
  • #SaaS Security
  • #Consent Governance

Browse Other Tags

#Detection Engineering#Credential Theft#Identity#Supply Chain#AiTM#Campaign Analysis#Infrastructure Intelligence#MFA Bypass#SaaS Security#Tradecraft Labs#ClickFix#Developer Security