Microsoft warns of OAuth phishing campaigns that can bypass email and browser defenses – says “these campaigns demonstrate that this exploit is operational, not theoretical”
Microsoft warns that hackers are abusing the OAuth redirection feature to deliver malware Phishing emails with the theme Teams recordings or 365 reset redirect victims to attacker-controlled websites Payload dropped via ZIP archives with LNK shortcuts and HTML smuggling; last stage connects to external C2 Hackers are abusing a redirection feature in OAuth to infect […]









