FeedThe New Phishing Click: How OAuth Consent Bypasses MFA...
The Hacker News

The New Phishing Click: How OAuth Consent Bypasses MFA

📅 19 May 2026 at 11:30 UTC📰 The Hacker NewsView original source ↗
The New Phishing Click: How OAuth Consent Bypasses MFA

In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries. The targets of the platform received a message asking them to enter a short code at microsoft.com/devicelogin and complete their normal MFA challenge, then walked away believing they had verified a

Read the full article

This is a curated summary. The complete article is available at The Hacker News.

Read on The Hacker News
← Back to feed