pushsecurity.com Emerging Threat of Authorization Phishing in 2026
Article Content
- •Authorization phishing targets OAuth consent flows post-authentication.
- •Over 30 distinct device code phishing kits are now available to attackers.
- •Security teams must adapt to evolving phishing tactics to protect against these threats.
In 2026, a new class of phishing attacks known as authorization phishing has gained traction, targeting the OAuth consent flow after users have already authenticated. Attackers leverage device code phishing techniques to bypass traditional authentication controls, including MFA and phishing-resistant passkeys. This shift in tactics reflects a broader trend as attackers adapt to improved security measures. The rise of authorization phishing is evidenced by over 30 distinct kits now available, with ConsentFix being a notable tool that has been commoditized for criminal use. Security teams are urged to enhance their detection capabilities to combat these evolving threats. The articles highlight that while traditional phishing methods remain prevalent, the focus is shifting towards exploiting authorization layers, making it for organizations to stay vigilant.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Apt29, ClickFix and Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is authorization phishing?
How can we detect authorization phishing?
What tools are being used for these attacks?
Continue Reading
Russia's AI-Driven Cyber Espionage Targets Ukraine and Europe A Russian-linked hacking group, identified as GTG-20006, has utilized Anthropic's Claude AI to automate cyber espionage against over 20 organizations, primarily in Ukraine and Europe. The group targeted Ukrainian government officials, military personnel, and drone manufacturers through sophisticated phishing and…
Cisco Talos Launches CAIRN to Combat AI-Integrated Malware On September 22, 2026, Cisco Talos released CAIRN, an open-source toolkit designed to hunt, classify, and track AI-integrated malware. The first documented malware analyzed with CAIRN is CLOSEDQUORUM, a Windows implant that autonomously delegates command-and-control decisions to commercial large language models…