Phishing campaign exploits OAuth redirection to bypass defenses

2026-03-04T21:43:50Z2a18fa44e02a40c032eda2c15e4474f69230c482e0bd6c051c98667d89a73556
CVE-2026-0628CVE-2026-21385CVE-2026-21513APT28APT37AndroidChromeClawJackedGemini LiveMSHTMLOAuth redirectionOdido breach (Netherlands) Frances? No, Netherlands)","Europol"OpenClawQualcommRuby JumperShinyHuntersUSB implantZoho WorkDriveair-gapped breachdata leakdata theftgovernment targetingpatch releasedphishingzero-day

What happened

Multiple high-impact incidents and active campaigns were reported: threat actors are abusing OAuth redirection in targeted phishing against government/public-sector users to bypass email/browser defenses; Google confirmed active exploitation of a high-severity Qualcomm Android flaw (CVE-2026-21385); a Chrome extension vulnerability (CVE-2026-0628) could let malicious extensions hijack the Gemini Live assistant to spy and exfiltrate files; and Russia-linked APT28 exploited an MSHTML zero-day (CVE-2026-21513) before patching. North Korea–linked APT37 (Ruby Jumper) combined Zoho WorkDrive C2 anda

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
2a18fa44e02a40c032eda2c15e4474f69230c482e0bd6c051c98667d89a73556
Enrichment time
2026-03-04T21:43:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.