ConsentFix v3 attacks target Azure with automated OAuth abuse
The ConsentFix v3 attack targets Microsoft Azure by automating OAuth abuse, tricking victims into granting access via a fake Microsoft login flow. This improved technique uses Pipedream for automation, allowing attackers to obtain tokens and access compromised accounts without needing passwords, even with MFA enabled.