← Front PageThreat Intel Desk
Threat Intel
The New Phishing Click: How OAuth Consent Bypasses MFA
EvilTokens platform compromised 340 Microsoft 365 organizations using OAuth consent manipulation, bypassing traditional MFA protections through device registration flows.
Summary written by editorial AI · Source link below
In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries.
The targets of the platform received a message asking them to enter a short code at microsoft.com/devicelogin and complete their normal MFA challenge, then walked away believing they had verified a
Continue at the source
Read the full report at THN (Feedburner)External link — opens at THN (Feedburner) in a new tab.
§
Continue with
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d