# Don’t trust that app! Page: https://stenobird.com/podcast/research-saturday-1377435/don-t-trust-that-app Text version: https://stenobird.com/podcast/research-saturday-1377435/don-t-trust-that-app.md Podcast: [Research Saturday](https://stenobird.com/podcast/research-saturday-1377435) Published: 2026-01-03T06:00:00+00:00 Episode link: https://thecyberwire.com/podcasts/research-saturday/392/notes Audio file: https://pdst.fm/e/pdrl.fm/6ec23a/traffic.megaphone.fm/CYBW5944104831.mp3?updated=1766083362 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/don-t-trust-that-app Duration seconds: 1241 ## Resource While our team is out on winter break, please enjoy this episode of Research Saturday. Today we are joined by ⁠⁠Selena Larson⁠⁠, co-host of ⁠⁠Only Malware in the Building⁠⁠ and Staff Threat Researcher and Lead Intelligence Analysis and Strategy at ⁠⁠Proofpoint⁠⁠, sharing their work on "Microsoft OAuth App Impersonation Campaign Leads to MFA Phishing." Proofpoint researchers have identified campaigns where threat actors use fake Microsoft OAuth apps to impersonate services like Adobe, DocuSign, and SharePoint, stealing credentials and bypassing MFA via attacker-in-the-middle phishing kits, mainly Tycoon. These attacks redirect users to fake Microsoft login pages to capture credentials, 2FA tokens, and session cookies, targeting nearly 3,000 Microsoft 365 accounts across 900 environments in 2025. Microsoft’s upcoming security changes and strengthened email, cloud, and web defenses, along with user education, are recommended to reduce these risks. The research can be found here: ⁠⁠⁠⁠Microsoft OAuth App Impersonation Campaign Leads to MFA Phishing Learn more about your ad choices. Visit megaphone.fm/adchoices ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/don-t-trust-that-app/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/research-saturday-1377435/don-t-trust-that-app.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.