New OAuth-Based Attack Let Hackers Bypass Microsoft Entra Authentication Flows to Steal Keys
ID: 3f582ccb-6732-574b-b84d-6d6634a8643f
STIX ID: report--3f582ccb-6732-574b-b84d-6d6634a8643f
Feed Name: cybersecurityNews.com
ConsentFix is an OAuth authorization-code theft technique against Microsoft Entra where attackers serve a malicious Entra login URL (targeting Azure CLI/ARM) via phishing; after a user authenticates, an error page containing the authorization code is exposed and the attacker persuades the user to reveal it, allowing the adversary to redeem tokens from a separate IP. The report details how this method bypasses Conditional Access and device compliance controls and recommends detection by correlating paired interactive and non-interactive Azure sign-in events (same SessionID/ApplicationID/UserID) within the ~10-minute code validity window.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
