{"podcast":{"title":"GREY Journal Daily News Podcast","slug":"grey-journal-daily-news-podcast-6927761","podcast_index_feed_id":6927761,"rss_url":"https://feeds.acast.com/public/shows/665dda1b3ce6480013459039","website_url":"https://shows.acast.com/grey-journal-daily-news","image_url":"https://assets.pippa.io/shows/665dda1b3ce6480013459039/1717644637445-1b845bfe8616f8bc0e179bd1a9d8bfbd.jpeg","author":"GREY Journal","episode_count":1337,"summary":"From our Manhattan news studio, welcome to the GREY Journal Daily News Podcast! We bring you digestible news and business insights tailored for ambitious entrepreneurs and CEOs. Hosted on Acast. See acast.com/privacy for more information.","last_synced_at":"2026-07-25T04:18:01.614362+00:00","page_url":"https://stenobird.com/podcast/grey-journal-daily-news-podcast-6927761"},"episode":{"title":"How Should SaaS Leaders Respond to OAuth Abuse?","slug":"how-should-saas-leaders-respond-to-oauth-abuse","published_at":"2026-07-14T19:17:09+00:00","page_url":"https://stenobird.com/podcast/grey-journal-daily-news-podcast-6927761/how-should-saas-leaders-respond-to-oauth-abuse","show_page_url":"https://stenobird.com/podcast/grey-journal-daily-news-podcast-6927761","url":"https://greyjournal.net/news/","audio_url":"https://sphinx.acast.com/p/open/s/665dda1b3ce6480013459039/e/6a568b35f821a8210944a108/media.mp3","summary":"Microsoft warned that the hacking group ShinyHunters abused OAuth in SaaS environments to gain persistent access through malicious applications. The company described attacks that rely on user or administrator consent to grant high value permissions, allowing access to email, files, calendars, and directories without using passwords. Microsoft advised limiting who can register applications, requiring administrator approval for risky scopes, preferring publisher verified apps, and applying Conditional Access to consent flows. Detection steps include auditing Enterprise Applications, reviewing OAuth consent logs and token usage, and removing malicious service principals while revoking tokens. Founders should inventory third party integrations, enforce least privilege scopes through centralized approvals, and require security commitments from vendors. Training employees on consent prompts and running incident exercises help strengthen response and reduce business risk. Learn more on this news by visiting us at: https://greyjournal.net/news/ Hosted on Acast. See acast.com/privacy for more information.","meta_description":"Microsoft warned that the hacking group ShinyHunters abused OAuth in SaaS environments to gain persistent access through malicious applications. The compa…","key_points":[],"chapters":[],"topics":[],"duration_seconds":75,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/grey-journal-daily-news-podcast-6927761/episodes/how-should-saas-leaders-respond-to-oauth-abuse/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/grey-journal-daily-news-podcast-6927761/how-should-saas-leaders-respond-to-oauth-abuse.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}