logo

New OAuth-Based Attack Let Hackers Bypass Microsoft Entra Authentication Flows to Steal Keys

ID: 3f582ccb-6732-574b-b84d-6d6634a8643f

STIX ID: report--3f582ccb-6732-574b-b84d-6d6634a8643f

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-01-08

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

ConsentFix is an OAuth authorization-code theft technique against Microsoft Entra where attackers serve a malicious Entra login URL (targeting Azure CLI/ARM) via phishing; after a user authenticates, an error page containing the authorization code is exposed and the attacker persuades the user to reveal it, allowing the adversary to redeem tokens from a separate IP. The report details how this method bypasses Conditional Access and device compliance controls and recommends detection by correlating paired interactive and non-interactive Azure sign-in events (same SessionID/ApplicationID/UserID) within the ~10-minute code validity window.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.