The OAuth Phishing Trap: Proofpoint Exposes AiTM Attacks That Bypass MFA to Hijack Cloud Accounts
ID: 1b79e7a7-aa8f-5cc3-8be7-2750cda340b7
STIX ID: report--1b79e7a7-aa8f-5cc3-8be7-2750cda340b7
Feed Name: securityonline.info
Proofpoint details widespread AiTM OAuth phishing campaigns that abuse maliciously registered Azure OAuth applications and the Tycoon PhaaS to proxy Microsoft 365 login flows, harvest credentials and MFA/session tokens, and achieve account takeovers; telemetry shows ~3,000 attempted compromises across ~900 tenants with a >50% observed success rate, and recommended defenses include blocking impersonation emails, detecting malicious OAuth apps, web isolation, user training, and adoption of phishing-resistant FIDO keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
