Story perspectives
New ConsentFix Phishing Attack Threatens Microsoft Accounts
12/12/2025
1 of 1
Story summary
- Push Security identified a new phishing attack called ConsentFix that can take over Microsoft accounts without capturing passwords or triggering MFA.
- The attack tricks victims into logging into Azure CLI to obtain an OAuth authorization code via a localhost URL.
- It bypasses defenses by using Google Search to deliver the lure and by exploiting trusted first-party applications.
- Push Security warns the technique evades detection and monitoring.
