Dark Reading
MFA Won't Save You from OAuth Consent Abuse
MFA does not prevent users from authorising malicious or excessively privileged OAuth applications through legitimate consent screens. Such permissions can provide persistent API-based access to email, files, cloud environments, and business applications without stealing passwords or deploying malware. Organisations should restrict user consent, enforce least-privilege scopes, require admin approval for high-risk applications, monitor grants, and revoke suspicious tokens quickly.
Cybersecurity Dive
Manufacturers Make Patching Progress, but Identity Management Still Major Weakness
Black Kite research finds that manufacturers have improved patching but remain exposed through identity, credential, remote-access, and configuration weaknesses. The findings highlight the need to combine patching with stronger IAM, exposed-service reduction, credential protection, and supplier-risk controls.
The Wall Street Journal
Europe’s Most Valuable Startup Gave Data to a Scammer. Now It Faces a Shakedown.
The article reports that Revolut disclosed customer data to a person allegedly impersonating a government agency, followed by an extortion demand. The incident shows that sensitive-data exposure can result from social engineering and weak verification, not only technical compromise. Stronger authentication of official requests, dual approval, data minimisation, and audit trails are important safeguards.