The OAUTh Problem You Didn't Know You Have | Evier Tabora

The OAUTh Problem You Didn't Know You Have Presenter: Evier Tabora OAuth is everywhere. From logging into apps with Google or Microsoft to connecting third party tools, most people assume what they grant access to is safe. But what if that trust is misplaced? In this talk, Evier Tabora breaks down a lesser-known risk in OAuth that many organizations overlook. Instead of exploiting traditional vulnerabilities, attackers can abuse how permissions are granted to access data they should not normally be able to see. The session walks through how trusted providers and ecosystems can be leveraged to gain unintended access to files and resources. Because everything looks legitimate on the surface, these attacks can be difficult to detect and often go unnoticed. You will see how small permission decisions can lead to much larger exposure, especially when users are not fully aware of what access they are granting. This creates a hidden risk that exists in many environments today. The talk also covers practical ways to reduce this risk by evaluating OAuth integrations, limiting permissions, and improving visibility into what access is actually being granted. If your organization uses OAuth, this is likely a problem you already have. You just may not know it yet. 00:00 – Intro: The OAuth Problem You Didn’t Know You Had 05:19 – How OAuth Actually Works in Practice 10:38 – Where OAuth Starts to Break Down 15:57 – Real-World Risk: Tokens, Access, and Abuse 21:15 – AI Tools, Integrations, and Expanding Attack Surface 26:34 – Why OAuth Becomes a Hidden Entry Point 31:52 – Detection Challenges and Visibility Gaps #cybersecurity #infosec #oauth #cloudsecurity #identitysecurity #securityawareness #cyberrisk ///Black Hills Infosec Socials Twitter:   / bhinfosecurity   Mastodon: https://infosec.exchange/@blackhillsi... LinkedIn:   / antisyphon-training   Discord:   / discord   ///Black Hills Infosec Shirts & Hoodies https://spearphish-general-store.mysh... ///Black Hills Infosec Services Active SOC: https://www.blackhillsinfosec.com/ser... Penetration Testing: https://www.blackhillsinfosec.com/ser... Incident Response: https://www.blackhillsinfosec.com/ser... ///Backdoors & Breaches - Incident Response Card Game Backdoors & Breaches: https://www.backdoorsandbreaches.com/ Play B&B Online: https://play.backdoorsandbreaches.com/ ///Antisyphon Training Pay What You Can: https://www.antisyphontraining.com/pa... Live Training: https://www.antisyphontraining.com/co... On Demand Training: https://www.antisyphontraining.com/on... Antisyphon Discord:   / discord   Antisyphon Mastodon: https://infosec.exchange/@Antisy_Trai... ///Educational Infosec Content Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/ Wild West Hackin' Fest YouTube:    / wildwesthackinfest   Antisyphon Training YouTube:    / antisyphontraining   Active Countermeasures YouTube:    / activecountermeasures   Threat Hunter Community Discord:   / discord   Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: https://wildwesthackinfest.com/