‘ConsentFix’ Attack Hijacks Microsoft Accounts via Azure CLI OAuth
A new attack dubbed “ConsentFix” uses the Azure CLI OAuth app to hijack Microsoft accounts without needing a password or bypassing multi-factor authentication (MFA) verifications. Cybersecurity firm Push Security discovered this variant, which steals OAuth 2.0 authorization codes used to obtain an Azure CLI access token. The ConsentFix attack starts with a fake Cloudflare Turnstile … Read more