{"podcast":{"title":"Research Saturday","slug":"research-saturday-1377435","podcast_index_feed_id":1377435,"rss_url":"https://feeds.megaphone.fm/cyberwire-research-saturday","website_url":"https://thecyberwire.com/podcasts/research-saturday","image_url":"https://megaphone.imgix.net/podcasts/720fb496-dcfb-11ea-a475-bbdae30535a9/image/8f3cd4038c81bba2a8ea4ca89f3e23c4.png?ixlib=rails-4.3.1&max-w=3000&max-h=3000&fit=crop&auto=format,compress","author":"N2K Networks Inc.","episode_count":458,"summary":"Every Saturday, we sit down with cybersecurity researchers to talk shop about the latest threats, vulnerabilities, and technical discoveries.","last_synced_at":"2026-07-26T04:20:01.844149+00:00","page_url":"https://stenobird.com/podcast/research-saturday-1377435"},"episode":{"title":"Don’t trust that app!","slug":"don-t-trust-that-app","published_at":"2026-01-03T06:00:00+00:00","page_url":"https://stenobird.com/podcast/research-saturday-1377435/don-t-trust-that-app","show_page_url":"https://stenobird.com/podcast/research-saturday-1377435","url":"https://thecyberwire.com/podcasts/research-saturday/392/notes","audio_url":"https://pdst.fm/e/pdrl.fm/6ec23a/traffic.megaphone.fm/CYBW5944104831.mp3?updated=1766083362","summary":"While our team is out on winter break, please enjoy this episode of Research Saturday. Today we are joined by ⁠⁠Selena Larson⁠⁠, co-host of ⁠⁠Only Malware in the Building⁠⁠ and Staff Threat Researcher and Lead Intelligence Analysis and Strategy at ⁠⁠Proofpoint⁠⁠, sharing their work on \"Microsoft OAuth App Impersonation Campaign Leads to MFA Phishing.\" Proofpoint researchers have identified campaigns where threat actors use fake Microsoft OAuth apps to impersonate services like Adobe, DocuSign, and SharePoint, stealing credentials and bypassing MFA via attacker-in-the-middle phishing kits, mainly Tycoon. These attacks redirect users to fake Microsoft login pages to capture credentials, 2FA tokens, and session cookies, targeting nearly 3,000 Microsoft 365 accounts across 900 environments in 2025. Microsoft’s upcoming security changes and strengthened email, cloud, and web defenses, along with user education, are recommended to reduce these risks. The research can be found here: ⁠⁠⁠⁠Microsoft OAuth App Impersonation Campaign Leads to MFA Phishing Learn more about your ad choices. Visit megaphone.fm/adchoices","meta_description":"While our team is out on winter break, please enjoy this episode of Research Saturday. Today we are joined by ⁠⁠Selena Larson⁠⁠, co-host of ⁠⁠Only Malware…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1241,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/research-saturday-1377435/episodes/don-t-trust-that-app/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/research-saturday-1377435/don-t-trust-that-app.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}