The New Phishing Click: How OAuth Consent Bypasses MFA
ID: f02bbb63-1730-5071-89b7-d07e4064392e
STIX ID: report--f02bbb63-1730-5071-89b7-d07e4064392e
Feed Name: The Hacker News
This article describes the emergence and impact of consent phishing (OAuth grant abuse), highlighting a PhaaS named EvilTokens that compromised 340+ Microsoft 365 tenants by tricking users into granting OAuth scopes and obtaining refresh tokens that bypass MFA and survive password resets. It explains how consent screens and AI/third-party integrations normalize excessive privileges, creates cross-application 'toxic combinations', and recommends continuous OAuth-grant visibility, token-level revocation, re-consent policies, and specialized AI-security platforms to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
