Skip to content
Episode 60

Cloud Persistence: Rogue MFA, OAuth and Passkeys

October 2nd, 2026

40 mins 20 secs

Season 3

Your Hosts

About this Episode

Welcome back to the Scinary Information Nexus! This week, the crew had to toss their planned agenda out the window. Richard, Joseph, Mario, and Brazos jump in for an emergency breakdown of an aggressive phishing wave battering K-12 school districts and higher ed institutions.

Attackers are weaponizing legitimate Google Docs and using Adversary-in-the-Middle (AiTM) proxies to harvest credentials and bypass traditional MFA. Because the phishing notifications originate straight from Google's own servers, they breeze past standard SPF, DKIM, and DMARC checks. Once inside, threat actors hijack internal distribution lists to spread laterally, creating a virtual denial of service for IT teams through sheer operational attrition.

Even worse, standard password resets aren't cutting it. Attackers are locking in persistent cloud access with rogue OAuth application grants, hidden MFA enrollments, and rogue device keys. We break down how this campaign works, examine the CAPTCHA fatigue driving users straight toward ClickFix social engineering lures, and share concrete hardening tactics you can implement inside Google Admin right now to lock down your domain.

In this episode:

  • Anatomy of the breach: How weaponized Google Docs bypass email authentication filters.
  • AiTM in action: Why traditional MFA fails against adversary-in-the-middle session theft.
  • Cloud persistence traps: How rogue OAuth permissions and device keys survive password resets.
  • Denial of service by attrition: The hidden toll of high-velocity account takeovers on IT teams.
  • CAPTCHA fatigue: How flagged outbound IPs prime users for ClickFix social engineering.
  • Hardening Google Admin: Disabling student directory lookups and ditching formulaic passwords.
  • The Google Workspace dilemma: Free EDU tiers and gated security features.

Has your organization noticed a spike in AiTM phishing or Google Docs lures lately? Let us know in the comments how your team is responding!


Connect with Us:
https://www.scinary.com
https://x.com/scinarycyber
https://www.linkedin.com/company/scinarycyber/

00:00 Intro
01:45 Google Docs Phishing & AiTM MFA Bypass
07:00 Cloud Persistence: Rogue OAuth & Device Keys
11:45 IT Attrition & CAPTCHA Fatigue Risks
21:15 Hardening Google Admin & Zero Trust
33:45 Google Ecosystem & Prompt Injections

Cybersecurity #InfoSec #Phishing