Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

Hackers are exploiting OAuth loophole for persistent access – and resetting your password won’t save you

Tech Wavo by Tech Wavo
October 22, 2025
in Computers
0



  • Researchers have observed attackers weaponizing OAuth apps
  • Attackers gain access that persists even through password changes and MFA
  • This isn’t just a proof of concept – it’s been observed in the wild

Researchers at Proofpoint have discovered a tactic used by threat actors to weaponize OAuth applications in order to gain persistent access within compromised environments – where hackers can retain access even after MFA or a password reset is carried out.

This attack has the potential to be devastating, as an attacker with access to a cloud account could open the door for a series of other intrusions. This account access could then be used to create and authorize internal applications with custom permissions – allowing the access to files, communications, and sidestepping security.

Cybercriminals have increasingly used cloud account takeover (ATO) tactics in recent years – as it allows them to hijack accounts, exfiltrate information, and use this as a foothold for other attacks. Both frequency and severity has increased, with strategies fast evolving.


You may like

Persistent access

The researchers have developed a proof of concept to outline how this attack might look in the wild, building a tool that automates the creation of malicious internal applications within the breached cloud environment.

A real-world example was also discovered when experts detected a successful login attempt, which, based on threat intelligence, is likely to be associated with ‘Adversary-in-the-middle’ social engineering attacks.

“After approximately 4 days the user’s password was changed, following which we observed failed login attempts from a Nigerian residential IP address, suggesting the threat actor’s possible origin,” the researchers explain.

“However, the application remained active. This case study serves as a concrete example of the attack patterns discussed in our blog, demonstrating that these threats are not merely theoretical – but active, exploited risks in the current threat landscape.”

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

The only way to revoke access in these cases before the expiration of the secret credentials (which remain valid for two years) is by manually removing permissions, so make sure to consistently review and account permissions regularly and continuously monitor applications.

Best antivirus software header

The best antivirus for all budgets

Our top picks, based on real-world testing and comparisons
Previous Post

A four-pack of AirTags is on sale for the lowest price we’ve seen

Next Post

Steve Wozniak, Prince Harry and 800 others want a ban on AI ‘superintelligence’

Next Post
Steve Wozniak, Prince Harry and 800 others want a ban on AI ‘superintelligence’

Steve Wozniak, Prince Harry and 800 others want a ban on AI ‘superintelligence’

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

How one founder plans to save cities from flooding with terraforming robots

by Tech Wavo
November 7, 2025
0
How one founder plans to save cities from flooding with terraforming robots
Computers

Parts of San Rafael, a city just north of San Francisco, are sinking about half an inch per year. That...

Read more

4 ways to boost personal productivity in a distributed world

by Tech Wavo
November 7, 2025
0
4 ways to boost personal productivity in a distributed world
Computers

Today’s teams often include people in the same office, people working remotely in the same time zone, and people spread...

Read more

Get up to $330 off cordless vacuums thanks to Dyson early Black Friday deals

by Tech Wavo
November 7, 2025
0
Early sales include more than $290 off cordless vacuums
Computers

Dyson is holding an early Black Friday sale on vacuums and related products. Sure, Black Friday isn't for another month,...

Read more

This easy-to-miss Black Friday deal at Mint Mobile can save you 30% on your annual phone bill

by Tech Wavo
November 7, 2025
0
This easy-to-miss Black Friday deal at Mint Mobile can save you 30% on your annual phone bill
Computers

Tired of paying huge bucks for an unlimited plan you don't even use? One of the best prepaid carriers has...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock