Most Important ShinyHunters Detection 2026: Vishing-to-OAuth – Post-Reset Connected App Authorization

Detects a pattern associated with ShinyHunters/UNC6040, where a user authorizes a new or rarely-used OAuth connected application shortly after performing a help-desk initiated password reset or MFA re-enrollment, originating from a different geographic location.