ConsentFix Attack Exploits Azure CLI to Compromise Microsoft Accounts
First seen 12 Dec 2025, 18:53 UTC
•
•85% similarity
•20
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The ConsentFix attack is a new phishing technique that allows attackers to hijack Microsoft accounts by exploiting the Azure CLI app. This method bypasses traditional security measures such as passwords and multi-factor authentication, operating entirely within the browser context. Victims of this attack are primarily Microsoft account users.
ThreatCluster AI