{"id":3424,"date":"2024-05-06T11:01:20","date_gmt":"2024-05-06T16:01:20","guid":{"rendered":"https:\/\/www.darkreading.com\/identity-access-management-security\/microsoft-previews-feature-to-block-malicious-oauth-apps"},"modified":"2024-05-06T11:01:20","modified_gmt":"2024-05-06T16:01:20","slug":"microsoft-previews-feature-to-block-malicious-oauth-apps","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/05\/06\/microsoft-previews-feature-to-block-malicious-oauth-apps\/","title":{"rendered":"Microsoft Previews Feature to Block Malicious OAuth Apps"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltac8aaeda40b6417a\/64f15224f6f80e09d34fb125\/loginwithfacebookgoogletwitter-Richard_Levine-alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/microsoft-previews-feature-to-block-malicious-oauth-apps.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/microsoft-previews-feature-to-block-malicious-oauth-apps.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Threat actors are increasingly including malicious OAuth apps in their campaigns to break into cloud-based systems and applications. To address this growing problem, Microsoft is adding automated attack disruption capabilities to its extended detection and response (XDR) offering that can automatically deactivate malicious OAuth apps.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">OAuth (Open Authentication standard) provides automated logins to applications and systems via API tokens. OAuth authentication provides a secure way to authenticate users and protect their data by allowing automated logins to applications and systems via API tokens. OAuth allows users to access multiple accounts without entering credentials each time they log in.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, they are also being abused. Back in December, Microsoft Threat Intelligence discovered various attacks that compromised user accounts for Microsoft cloud services, allowing them to create, modify, and grant broad privilege access. Attackers were able to retain access to applications even after losing access to the account they initially breached. &nbsp;With that access, the threat actors were able to launch phishing and password-spraying attacks on those user accounts that lacked strong authentication. With elevated permissions, the attackers could launch spam campaigns with the victims&#8217; resources and domain names, or other wise establish persistence within the victim environment.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Once an OAuth app&nbsp;is given&nbsp;login permission, it can do&nbsp;a lot of&nbsp;things. And if you give permission to a malicious OAuth app, it can log in as you and operate within the system as if it&#8217;s you, and stopping that malicious activity is&nbsp;really, really&nbsp;important,&#8221; says Sherrod DeGrippo, director of Microsoft&#8217;s threat intelligence strategy.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Just last week, the online storage service&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/dropbox-breach-exposes-customer-credentials-authentication-data\" rel=\"noopener\">Dropbox warned<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;that an attacker had <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/dropbox-breach-exposes-customer-credentials-authentication-data?utm_source=linkedin&amp;utm_medium=referral&amp;utm_campaign=li_nl\" rel=\"noopener\">accessed customer credentials of its Dropbox Sign service<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and advised security professionals to rotate their API and OAuth keys and tokens.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Expanding Defender XDR Capabilities\">Expanding Defender XDR Capabilities<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Last year, Microsoft added automatic attack disruption capabilities to Defender XDR (formerly Microsoft 365 Defender) to remediate ransomware, business email compromise (BEC), and attacker-in-the-middle attacks, as well as detect an disrupt brute force attacks that use credential stuffing and password spray methods. Defender XDR now stops many ransomware and BEC attacks within three minutes, DeGrippo says. &nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The newest capability, which Microsoft is previewing during RSA Conference in San Francisco, Calif. this week, focuses on disrupting attacks against SaaS-based applications using malicious OAuth apps. Defender XDR would automatically disable the compromised OAuth app, thereby shutting the attacker out from further exploitation, Microsoft wrote in a post announcing the feature. &#8220;Not only does attack disruption now stop OAuth app attacks, but it can significantly disrupt more scenarios that involve a compromised user such as leaked credentials, stuffing and guessing,\u201d the company said.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Microsoft also added native protection for operational technology (OT) and industrial control systems (ICS) in Defender XDR. According to Microsoft, defenders can now detect and respond to threats across OT systems and analyze the security posture of their industrial control system from the Defender XDR portal.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Because attackers are using AI to accelerate the speed of their attacks, Microsoft officials say AI is necessary to keep pace. According to Forrester Research, the mean time to detect, respond, eradicate and recover from an attack on average is 63 days. And according to a recent analysis by Microsoft, attackers begin lateral movement within an organization within five minutes, while they can complete an entire attack chain within two hours.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;AI is leveraged heavily, not just within our detection capability but also within this disruption capability,&#8221; DeGrippo says . \u201cLike everything we do, we want to be faster than a threat actor, and AI is one of those things that absolutely gives you the power of speed.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/identity-access-management-security\/microsoft-previews-feature-to-block-malicious-oauth-apps\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat actors are increasingly including malicious OAuth apps in their<\/p>\n","protected":false},"author":12,"featured_media":3425,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-3424","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/microsoft-previews-feature-to-block-malicious-oauth-apps.jpg?fit=646%2C375&ssl=1",646,375,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/microsoft-previews-feature-to-block-malicious-oauth-apps.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/microsoft-previews-feature-to-block-malicious-oauth-apps.jpg?fit=300%2C174&ssl=1",300,174,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/microsoft-previews-feature-to-block-malicious-oauth-apps.jpg?fit=640%2C372&ssl=1",640,372,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/microsoft-previews-feature-to-block-malicious-oauth-apps.jpg?fit=640%2C372&ssl=1",640,372,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/microsoft-previews-feature-to-block-malicious-oauth-apps.jpg?fit=646%2C375&ssl=1",646,375,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/microsoft-previews-feature-to-block-malicious-oauth-apps.jpg?fit=646%2C375&ssl=1",646,375,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/microsoft-previews-feature-to-block-malicious-oauth-apps.jpg?fit=646%2C375&ssl=1",646,375,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/microsoft-previews-feature-to-block-malicious-oauth-apps.jpg?resize=646%2C375&ssl=1",646,375,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/microsoft-previews-feature-to-block-malicious-oauth-apps.jpg?resize=590%2C375&ssl=1",590,375,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/05\/microsoft-previews-feature-to-block-malicious-oauth-apps.jpg?fit=646%2C375&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3424","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=3424"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/3424\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/3425"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=3424"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=3424"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=3424"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}