OAuth 2.0 Access Tokens and the Principle of Least Privilege | by Andrea Chiarelli.
https://auth0.com/blog/oauth2-access-tokens-and-principle-of-least-privilege/

OAuth 2.0 Access Tokens and the Principle of Least Privilege | by Andrea Chiarelli.
https://auth0.com/blog/oauth2-access-tokens-and-principle-of-least-privilege/
If you manage a web application that uses OpenStreetMap.org authentication or independently use the OpenStreetMap-website code, please see our recent security notice: https://operations.osmfoundation.org/2025/07/11/security-notice.html #OpenStreetMap #OSM #Security #OAuth
OAuth in the MCP C# SDK: Simple, Secure, Standard | by Den Delimarsky.
Demain c'est l'été, il est temps de faire le point sur le mécénat et les contributions à des logiciels libres commis par l'équipe de Yaal Coop ces 3 derniers mois ! Au menu, beaucoup de choses autour d'outils #oidc et #oauth en #python
https://yaal.coop/blog/dernieres-contributions-logiciels-libres-printemps-2025
#Hollo 0.6.0 is coming soon!
We're putting the finishing touches on our biggest security and feature update yet. Here's what's coming:
New features
Important notes for update
SECRET_KEY
requirements (44+ chars)Special thanks to @thisismissem for the extensive OAuth improvements that help keep the #fediverse secure and compatible!
Full changelog and upgrade guide coming with the release.
I'm not easily swearing, but how can I put this: sending infra emails from a data center to addresses managed by #Microsoft 365 is crazy. MS dislikes #SMTP AUTH, ok, and so begins the #OAuth journey to get the #postfix mail relay to embrace OAuth
The best idea so far is to write a script that acts as a proxy between postfix and MS, sending emails via the MS #GraphAPI. Undoubtedly much more secure and, just as undoubtedly, absolutely no vendor lock-in for something as simple as SMTP ... WTF!!
I got n8n working with LinkedIn, Mastodon, etc. Can I get it to work with Fitbit?
Hackers abuse #OAuth 2.0 workflows to hijack #Microsoft365 accounts
Just did a big rewrite of a docs page on dynamic identity providers in Duende #identityserver.
That was fun to dive in, and makes me appreciate the thought put in to designing both #aspnetcore and IdentityServer itself.
https://docs.duendesoftware.com/identityserver/ui/login/dynamicproviders/
(also big thanks to @khalidabuhakmeh for the fantastic preview images on new docs pages)
Phishers have found a clever way to spoof Google — and their emails pass all security checks.
A new DKIM replay phishing attack abuses Google’s own OAuth infrastructure to send fake messages that look 100% legitimate, including passing DKIM authentication.
What happened:
- A phishing email was sent from “no-reply@google.com”
- It appeared in the user’s inbox alongside real Google security alerts
- The message linked to a fake support portal hosted on sites[dot]google[dot]com — a Google-owned domain
- The attacker used Google OAuth to trigger a real security alert to their inbox, then forwarded it to victims
Why this matters:
- DKIM only verifies the headers, not the envelope — allowing this spoof to work
- The phishing site was nearly indistinguishable from Google’s actual login portal
- Because the message was signed by Google and hosted on a Google domain, it bypassed most users’ suspicions
- Similar tricks have been used with PayPal and other platforms, raising broader concerns
Google has since acknowledged the issue and is working on a fix. But this attack is a reminder:
Even the most secure-looking emails can be fraudulent.
Even Google-signed emails can be weaponized.
At @Efani, we advocate for layered defense — because no one layer is ever enough.
@netzpolitik_feed Haben die @EUCommission Kollegen schon mal von #oauth gehört? Ein großer Teil der Anfrage-Verwaltung ist damit technisch schon gelöst.
Cyberkriminelle nutzen aktuell gefälschte OAuth-Anwendungen, die sich als bekannte Dienste wie Adobe Acrobat, Adobe Drive oder DocuSign ausgeben. Ziel dieser Angriffe ist es, sich Zugriff auf Microsoft-365-Konten zu erschleichen. Im Beitrag erfährst du auch, wie du dich vor solchen Angriffen schützen kannst.
If you had to explain #OAuth2 to a relatively new SWE who only had a bit of experience interacting with public APIs from a frontend UI, are there any specific beginner-friendly online resources you'd recommend to them?
I'm presenting at the Wellington Python New Zealand meetup on Thursday evening, so if you're in town come along and cheer.
The subject is integrating #OAuth into a #Django project : what OAuth is and how it works; a good approach to integrating it into a Django project ; and what benefits it brings.
Although the talk with be Django-centric I hope those attending will be able to contribute their experience of using OAuth in #Flask, #FastAPI etc.
Sign up is here : https://www.meetup.com/pythonnz-wellington/events/304242570/
#Fedi, looking for people with experience in #accessible software.
I have a friend with serious vision issues. Not blind, but can't easily read text that isn't 6+ inches high, and his vision is degrading. He is looking for a way to deal with email -- he's a writer -- because he says Gmail is now a nightmare to use even with a screen reader.
Preferred solution would be a mail program / #MUA that runs on Windows and supports #OAUTH authentication, so he can continue to use his Gmail address.
What's the MUA with the best #accessibility on Windows? Thunderbird brags about its support for screen readers and assistive technologies, so I had him try it, and he says it's almost as bad as Gmail - flashing colours, animating controls. I haven't personally touched Thunderbird in many years, so it was a surprise to me.
I use a text/console mail flow that relies on a local MTA, so nothing I use is of any use in this.
Thanks, appreciate any pointers.