Blumira Briefings

Iran-Linked Hacking, Microsoft OAuth, and Starkiller Phishing Suite - Blumira Briefings

• Blumira

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 15:22

Welcome to Blumira Briefings, your top headlines and trends for your security practice.

This week's episode:

- Pro-Russia threat actors have formed a loose coalition with Iran-nexus hacking groups in response to the bombing campaign launched by the U.S. and Israel on Iran.
- Hackers are abusing the legitimate OAuth redirection mechanism to bypass phishing protections in email and browsers to take users to malicious pages.
- Cybersecurity researchers have disclosed details of a new phishing suite called Starkiller that proxies legitimate login pages to bypass multi-factor authentication (MFA) protections.

--

Like the new format? Have a security topic you want us to cover? Let us know in the comments!

--

Sources:
Pro-Russia actors team with Iran-linked hackers in attacks:
https://www.cybersecuritydive.com/news/pro-russia-actors-support-iran-nexus-hackers/813647/

Microsoft: Hackers abuse OAuth error flows to spread malware:
https://www.bleepingcomputer.com/news/security/microsoft-hackers-abuse-oauth-error-flows-to-spread-malware/

Starkiller Phishing Suite Uses AitM Reverse Proxy to Bypass Multi-Factor Authentication
https://thehackernews.com/2026/03/starkiller-phishing-suite-uses-aitm.html