Scworld Automated ConsentFix v3 Attack Targets Microsoft Azure Accounts
Article Content
- •ConsentFix v3 automates Microsoft Azure account hijacking using OAuth2 exploitation.
- •Attackers impersonate employees by gathering details and creating multiple service accounts.
- •Mitigation strategies include token binding and behavioral detection rules.
A new attack technique named ConsentFix v3 has emerged, automating the hijacking of Microsoft Azure accounts through sophisticated phishing methods. This attack builds on previous versions by enhancing automation and scalability to bypass security measures. It utilizes social engineering and exploits the OAuth2 authorization code flow to gain unauthorized access to user accounts. Attackers first identify valid tenant IDs and gather employee details for impersonation. They create multiple accounts across various services, leveraging Pipedream as a central tool for automation. The phishing scheme involves a page hosted on Cloudflare that mimics the Microsoft/Azure interface, tricking victims into pasting a localhost URL containing an OAuth authorization code. Once the code is captured, it is exchanged for tokens that grant access to compromised environments. The full impact of this attack is still being assessed, and mitigation strategies are recommended. As of now, it is unclear if this variant has gained widespread adoption among cybercriminals.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…