LowNews
OAuth grants pile up faster than you can review them. Here's how to keep up.
- Published
- Record updated
Summary
Nudge Security, a vendor, promotes its product for governing OAuth grants that employees create when they approve third-party apps. The article cites an attack in which a compromised OAuth token from the third-party AI tool Context.ai let an attacker into Vercel after one employee had connected it to their Google Workspace account. It also reports that employees create an average of 88 OAuth grants each, 31 with data-level permissions.
Mitigation
Nudge Security provides OAuth grant visibility, including dormant grants, and surfaces API keys, service accounts and remote MCP server connections. The source does not describe any other mitigation beyond this product.
Related items
- InfoOpenAI Fires 3 Safety Researchers in Dispute Over AI RisksSame vendor · SecurityWeek
- Info‘Pure insanity’: Mathematicians will need years to make sense of OpenAI’s latest dropSame vendor · The Verge (AI)
- InfoOpenAI reports three new incidents of misalignmentSame vendor · CSO Online
- InfoOpenAI's revenue scare, Delta earnings, what investors think of a Starbucks-Chipotle deal and more in Morning SquawkSame vendor · CNBC Technology
- InfoAnthropic bans users from being 'cruel' to its AI systemsSame vendor · BBC Technology