The New Phishing Click: How OAuth Consent Bypasses MFA | HappeningNow.news
Published Date: May 20, 2026

Cybersecurity The Hacker News May 19, 2026

The New Phishing Click: How OAuth Consent Bypasses MFA

In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live.

AI Summary Powered by Happening Now AI

In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries.  The targets of the platform received a message asking them to enter a short code at microsoft.com/devicelogin and complete their normal MFA challenge, then walked away believing they had verified a

Read full article on The Hackernews

AI summaries can be wrong sometimes—always verify important details using the source article.