🚨 BREAKING: Russian Hackers Use Simple Copy-Paste Trick to Steal Your Entire Microsoft Account 🚨
A sophisticated phishing attack called ConsentFix exploits OAuth vulnerabilities by tricking users into copying and pasting a malicious URL that contains their Microsoft authorization code. Attackers exchange this code for access tokens, gaining full account access without passwords or MFA, and the technique is already being used by APT29 (Cozy Bear) and other threat actors.
- https://www.hendryadr...