threat-intel
The New Phishing Click: How OAuth Consent Bypasses MFA
In February 2026, a phishing-as-a-service platform, EvilTokens, compromised over 340 Microsoft 365 organizations across five countries by exploiting OAuth consent screens. Attackers gained access to valid refresh tokens…
High
