Find notable cyber news and cases, enriched with sources, timelines, and signals.

ConsentFix browser-native OAuth consent phishing campaign

Campaign
First reported
Last updated
Happening score
H score 23
1 unique sources, 2 articles

Summary

Hide ▲

The ConsentFix campaign is a ClickFix-style OAuth consent phishing operation that hijacks Microsoft accounts by abusing the Azure CLI OAuth app. In the reported flow, victims land on a compromised legitimate website, pass a fake Cloudflare Turnstile check, and are guided to complete a Microsoft sign-in flow that yields an OAuth authorization code. Attackers then exchange that code for account access, bypassing the need for a password or MFA. The activity was described by Push Security and includes filtering for intended targets, with defenders advised to monitor unusual Azure CLI logins and legacy Graph scopes.

Related Happenings

LastPass and Bitwarden users targeted by fake-security-notice phishing campaign

Campaign
H score31 First: 14.07.2026 18:31 Last: 14.07.2026 18:31 Sources 1

About this happening: An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...

Jalisco and OmegaLord Microsoft 365 phishing kits

Malware Activity
H score27 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...

ShinyHunters-linked Salesforce intrusion campaign

Campaign
H score45 First: 14.07.2026 09:19 Last: 14.07.2026 09:19 Sources 1

About this happening: A ShinyHunters-linked campaign is abusing Salesforce trust relationships to access CRM data across retail, education, and manufacturing tenants. The operation combines...

GPPStorm Google Partners enrollment phishing campaign

Campaign
H score33 First: 13.07.2026 16:03 Last: 13.07.2026 16:03 Sources 1

About this happening: GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and st...

Microsoft Entra OAuth Client ID spoofing campaign

Campaign
H score58 First: 13.07.2026 16:00 Last: 13.07.2026 16:00 Sources 1

About this happening: A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...

Timeline

  1. 14.01.2026 17:01 3 articles · 6mo ago

    ConsentFix public debrief and campaign recap

    Initial Disclosure

    Push Security described ConsentFix, a browser-native OAuth consent phishing campaign that used ClickFix-style social engineering to hijack Microsoft accounts, ran across a large network of compromised websites, and was detected across multiple customer estates; the disclosure also noted a Russian state-affiliated APT29 linkage and recommended enabling AADGraphActivityLogs, hunting for Azure CLI and other first-party Microsoft app IDs, and tightening Conditional Access around vulnerable Microsoft apps.

    Show sources