Most Important ShinyHunters Detection 2026: Vishing-to-OAuth – Post-Reset Connected App Authorization
Detects a pattern associated with ShinyHunters/UNC6040, where a user authorizes a new or rarely-used OAuth connected application shortly after performing a help-desk initiated password reset or MFA re-enrollment, originating from a different geographic location.
YARA-L

