Cybersecurity News

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

Tue, 14 Jul 2026 16:51:35 +0530
The Hacker News

At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry. The activity allows users to enumerate user accounts and validate stolen credentials in Microsoft Entra ID environments, without ever generating a successful sign-in event that would otherwise alert defenders. And bad actors have begun

Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read

Tue, 14 Jul 2026 14:32:48 +0530
The Hacker News

xAI's Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed. A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned the git bundle out of the intercepted request, and pulled back a file the agent had been told in plain terms not