Oauth Phishing
The latest Oauth Phishing coverage — news, analysis, and updates from the WindowsNews.AI desk.
Drag-and-Drop Attack Steals Microsoft 365 Access After You Pass MFA
Cybercriminals have figured out how to hijack Microsoft 365 accounts without ever touching a password—even if you've completed multi-factor authentication. A technique called ConsentFix, detailed...
FBI Warns Kali365 Phishing Kit Exploits Microsoft Device Code Flow to Slip Past MFA
The FBI’s Internet Crime Complaint Center (IC3) issued an urgent alert in May 2026 about Kali365, a newly identified phishing‑as‑a‑service platform that is systematically hijacking Microsoft...
ConsentFix v3 Phishing Toolkit Steals OAuth Codes to Bypass MFA in Microsoft Entra ID
A dangerous new phishing toolkit called ConsentFix v3 has surfaced, purpose-built to compromise Microsoft Entra ID (formerly Azure AD) accounts by automating the theft of OAuth 2.0 authorization...
ConsentFix Attack: How OAuth Phishing Targets Azure CLI & Microsoft Graph
Security researchers have uncovered a sophisticated new phishing technique called ConsentFix that weaponizes Microsoft's own OAuth authentication flows and the Azure Command-Line Interface (Azure...
Token Security Crisis: How Hackers Are Exploiting Digital Keys in Windows & Cloud Systems
Tokens have become the skeleton keys of modern digital systems—small opaque strings that grant access, carry identity claims, and enable automation across Windows environments, cloud platforms, and...
OAuth Token Security Crisis: Protecting Cloud APIs and DeFi from Sophisticated Attacks
Token security has rapidly evolved from a background technical concern to a critical frontline risk affecting every organization that relies on cloud identity systems, web APIs, AI services, or...
CoPhish Attack: How Copilot Studio Agents Enable OAuth Consent Phishing
Microsoft's Copilot Studio has become the latest vector for sophisticated OAuth consent phishing attacks, with security researchers identifying a technique they've dubbed "CoPhish" that weaponizes AI...
CoPhish Attack: How Microsoft Copilot Studio Can Be Weaponized for OAuth Token Theft
Microsoft's Copilot Studio has become the latest vector for sophisticated phishing attacks, with security researchers at Datadog Security Labs uncovering a method they've dubbed "CoPhish" that...
Researchers reveal CoPhish: Microsoft Copilot Studio weaponized for OAuth token theft via trusted domains
A sophisticated new phishing technique dubbed "CoPhish" has emerged, weaponizing Microsoft's legitimate Copilot Studio platform to execute convincing OAuth consent attacks that bypass traditional...
Azure App Mirage: Microsoft's Defense Against Unicode Spoofing in OAuth Phishing
A sophisticated new phishing technique targeting Microsoft Azure customers has exposed critical vulnerabilities in how organizations visually verify application authenticity during OAuth consent...
The 2025 Surge in Sophisticated Phishing Attacks Targeting Microsoft Accounts: Strategies and Defenses
In 2025, the battleground for digital security has shifted dramatically, with Microsoft account holders standing on the front lines of an escalating war against increasingly sophisticated phishing...
2025 Microsoft OAuth Phishing Attacks: Evolving Threats Beyond MFA
Phishing campaigns continue to evolve at a staggering pace, keeping security professionals on perpetual alert. In 2025, the latest surge in Microsoft OAuth-centric phishing attacks illustrates just...