Minacce · 134 giorni fa
MFA non è il punto di controllo qui. Un utente che accetta un prompt di consenso OAuth può consegnare un refresh token a lunga durata, quindi l’attaccante mantiene l’accesso limitato al tenant dopo che l’accesso appare normale e l’alerting resta silenzioso.
1 fonte che coprono questa storia
The New Phishing Click: How OAuth Consent Bypasses MFA
OAuth consent is the phishing vector MFA misses—long-lived tokens and cross-app access bypass trusted identity controls.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-05-19