Application SecurityBleeping Computer
9.5 — CRITICAL
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
ConsentFix and ClickFix attacks steal Microsoft 365 tokens in seconds using fake prompts and OAuth flows. Learn how these MFA bypass tactics work and how to defend against them. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A new attack variant, ConsentFix, targets Microsoft 365 OAuth consent flows, allowing attackers to hijack user accounts in just three seconds. The attacks rely on convincing users to complete a routine action that ultimately surrenders session access.
⚙️Technical Details
Affected Systems
Microsoft 365
Attack Vectors
Drag-and-drop link into browserOAuth consent flows
💥Impact Assessment
Severity: Critical
Who Is at Risk
Users of Microsoft 365 with OAuth consent flow enabled
🛡️Recommended Actions
1Verify the authenticity of links and prompts before completing any action
2Enable two-factor authentication for Microsoft 365 accounts
3Regularly review and update user permissions to prevent unauthorized access
📦Affected Products
Microsoft 365
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
