logo

The New Phishing Click: How OAuth Consent Bypasses MFA

ID: f02bbb63-1730-5071-89b7-d07e4064392e

STIX ID: report--f02bbb63-1730-5071-89b7-d07e4064392e

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: [email protected] (The Hacker News)

...
...

This article describes the emergence and impact of consent phishing (OAuth grant abuse), highlighting a PhaaS named EvilTokens that compromised 340+ Microsoft 365 tenants by tricking users into granting OAuth scopes and obtaining refresh tokens that bypass MFA and survive password resets. It explains how consent screens and AI/third-party integrations normalize excessive privileges, creates cross-application 'toxic combinations', and recommends continuous OAuth-grant visibility, token-level revocation, re-consent policies, and specialized AI-security platforms to mitigate the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.