ConsentFix v3 attacks target Azure with automated OAuth abuse

The ConsentFix v3 attack targets Microsoft Azure by automating OAuth abuse, tricking victims into granting access via a fake Microsoft login flow. This improved technique uses Pipedream for automation, allowing attackers to obtain tokens and access compromised accounts without needing passwords, even with MFA enabled.

Edward Kiledjian @ekiledjian