Drooid Logo
Back to today’s briefing

Story perspectives

New ConsentFix Phishing Attack Threatens Microsoft Accounts

12/12/2025

37 6 Full Breakdown

1 of 1

Story summary
  • Push Security identified a new phishing attack called ConsentFix that can take over Microsoft accounts without capturing passwords or triggering MFA.
  • The attack tricks victims into logging into Azure CLI to obtain an OAuth authorization code via a localhost URL.
  • It bypasses defenses by using Google Search to deliver the lure and by exploiting trusted first-party applications.
  • Push Security warns the technique evades detection and monitoring.