New ConsentFix Technique Tricks Users Into Handing Over OAuth Tokens
ID: 97e00c26-666d-516d-9b2f-54ff1549cafb
STIX ID: report--97e00c26-666d-516d-9b2f-54ff1549cafb
Feed Name: KnowBe4 Blog
Researchers at Push Security uncovered a new OAuth consent phishing technique, dubbed "ConsentFix," that combines ClickFix-style prompts with OAuth authorization code theft: victims are tricked into copying a localhost URL containing an authorization code and pasting it into an attacker-controlled page, which establishes an OAuth connection to an attacker-controlled Azure CLI instance and compromises Microsoft accounts; the attack leverages legitimate first-party tooling and browser context, making it difficult to detect and mitigate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
