Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

The New Phishing Click: How OAuth Consent Bypasses MFA

EvilTokens platform compromised 340 Microsoft 365 organizations using OAuth consent manipulation, bypassing traditional MFA protections through device registration flows.

Summary written by editorial AI · Source link below

Filed by THN (Feedburner)1 min readRead at source ↗

In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries.

The targets of the platform received a message asking them to enter a short code at microsoft.com/devicelogin and complete their normal MFA challenge, then walked away believing they had verified a

Continue at the source
Read the full report at THN (Feedburner)

External link — opens at THN (Feedburner) in a new tab.

§
Continue with

More from the Threat Intel Desk