New Attack Technique “ConsentFix” Hijacks OAuth Consent Grants
ID: e197d62d-f06c-56d9-ace3-3f0a1cd785e8
STIX ID: report--e197d62d-f06c-56d9-ace3-3f0a1cd785e8
Feed Name: Arctic Wolf
**ConsentFix** is a browser-based phishing technique that social-engineers targeted users into copying a legitimate OAuth redirect URL (containing an authorization code) into a phishing page, enabling attackers to exchange the code for cloud access tokens and achieve account takeover without stealing passwords or MFA codes. The report outlines the attack flow, targeted-email gating, and recommended mitigations including never pasting authentication URLs into untrusted sites, deploying endpoint/EDR visibility, and user security awareness training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
