Phishing campaign exploits OAuth redirection to bypass defenses
2026-03-04T21:43:50Z•2a18fa44e02a40c032eda2c15e4474f69230c482e0bd6c051c98667d89a73556
CVE-2026-0628CVE-2026-21385CVE-2026-21513APT28APT37AndroidChromeClawJackedGemini LiveMSHTMLOAuth redirectionOdido breach (Netherlands) Frances? No, Netherlands)","Europol"OpenClawQualcommRuby JumperShinyHuntersUSB implantZoho WorkDriveair-gapped breachdata leakdata theftgovernment targetingpatch releasedphishingzero-day
What happened
Multiple high-impact incidents and active campaigns were reported: threat actors are abusing OAuth redirection in targeted phishing against government/public-sector users to bypass email/browser defenses; Google confirmed active exploitation of a high-severity Qualcomm Android flaw (CVE-2026-21385); a Chrome extension vulnerability (CVE-2026-0628) could let malicious extensions hijack the Gemini Live assistant to spy and exfiltrate files; and Russia-linked APT28 exploited an MSHTML zero-day (CVE-2026-21513) before patching. North Korea–linked APT37 (Ruby Jumper) combined Zoho WorkDrive C2 anda
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 2a18fa44e02a40c032eda2c15e4474f69230c482e0bd6c051c98667d89a73556
- Enrichment time
- 2026-03-04T21:43:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.