news.mlab.sh
Back to the feed
threat-intel

The New Phishing Click: How OAuth Consent Bypasses MFA

High
Image: The Hacker News
Summary

In February 2026, a phishing-as-a-service platform, EvilTokens, compromised over 340 Microsoft 365 organizations across five countries by exploiting OAuth consent screens. Attackers gained access to valid refresh tokens without triggering MFA, leveraging the instinctive nature of consent clicks and the lack of visibility into the consent layer by security controls. This represents a shift in phishing tactics, moving beyond simple credential theft to exploiting the granular permissions granted through OAuth, creating 'toxic combinations' that significantly expand the attack surface.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.