Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News The New Phishing Click: How OAuth Consent Bypasses MFA
The Hacker News
2 months ago

The New Phishing Click: How OAuth Consent Bypasses MFA

By info@thehackernews.com (The Hacker News)

In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries.  The targets of the platform received a message asking them to enter a short code at microsoft.com/devicelogin and complete their normal MFA challenge, then walked away believing they had verified a

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.