ConsentFix debrief: Insights from the new OAuth phishing attack
ID: e2d60db0-4184-5ffa-864c-aad4828388ba
STIX ID: report--e2d60db0-4184-5ffa-864c-aad4828388ba
Feed Name: Bleeping Computer
Push Security describes the discovery and mitigation of a large-scale OAuth consent-phishing technique named "ConsentFix" that tricks users into pasting Microsoft OAuth authorization responses into phishing pages; attackers then reuse those codes to obtain tokens and hijack accounts (including Azure CLI). The campaign — observed across a network of compromised sites and attributed to Russian state‑affiliated APT29 — leverages pre‑consented first‑party Microsoft apps and legacy scopes to evade default controls; the report summarizes community research, lists vulnerable app client IDs, and provides mitigations and monitoring recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
