Cloud
Attacks against cloud identity and productivity platforms — Microsoft 365, Google Workspace, Azure, AWS — including OAuth consent phishing, device-code abuse, token theft, and the "identity-first" intrusion patterns that treat the tenant, not the endpoint, as the ground floor.

CISA postmortem: nine alerts ignored, six months exposed
CISA's postmortem on its own six-month GitHub credential leak faults slow key rotation and nine ignored GitGuardian alerts — signal without intake.

WriteOut: One Preview Link Took Over Writer AI Accounts
SAND Security's WriteOut let a Writer AI agent preview link steal a signed-in user's session cookie across tenants. Writer has patched — the pattern hasn't.

GitLost: Public Issue Leaks Private GitHub Repo Data
Noma Security's GitLost shows how a public GitHub issue can trick Agentic Workflows into leaking private repos. Not patchable — scope your agent tokens today.

Dialogflow's Rogue Agent Flaw Is a Very Old Bug Class
Varonis' Rogue Agent finding in Google Dialogflow CX is a shared-runtime exec() escape — a bug class old enough to have graduated shared hosting.

Umbrij: ToddyCat Hijacks Gmail OAuth via Browser
Kaspersky Securelist detailed Umbrij, a ToddyCat post-compromise tool that self-grants Google Workspace OAuth tokens by driving a logged-in Chromium session. Nothing to patch. Plenty to audit.

ARToken PhaaS Targets M365 Device-Code Phishing
Cisco Talos exposed ARToken, a React-panel phishing-as-a-service tied to EvilTokens. Device code flow is the mechanic. Conditional Access is the fix, and most tenants still haven't turned it on.

ConsentFix + ClickFix: M365 Grants Outlive Resets
BleepingComputer covered two M365 hijack patterns and Opera's Paste Protect defense this week. The clipboard lane can be closed. The OAuth grant substrate underneath is unchanged.

Unpatched Argo CD Flaw Lets Unauth Cluster Takeover
Synacktiv disclosed an unpatched code-execution flaw in Argo CD's repo-server component. No fix, no CVE. Reachability of the internal port is the whole game.