ConsentFix v3 attacks target Azure with automated OAuth abuse

2026-05-02T19:24:00Z3ed3340641197e60f493bd2fc17f59e26b442ee942b4805824d24d5f98769b63
AI-assisted phishingALPHVANTSAzureBlackCatBluekitConsentFixFBI advisoryInstructureKB5083631KB5083769OAuth abuseOAuth consentRDPRemote DesktopSecuronixWindows 11backup failurescargo theftcloud securitydata breachphishingphishing kitransomwarethreat intelligence

What happened

Collection of security news highlights: a new wave of automated OAuth consent abuse called "ConsentFix v3" is being used to scale Azure account/resource compromise; Bluekit phishing-as-a-service adds AI-assisted campaign generation and 40+ templates; several cyber incidents and law-enforcement actions (Instructure incident disclosure and retraction, 15‑year‑old detained over ANTS data breach, sentencing for BlackCat-affiliated negotiators and a swatting ring leader). Microsoft released Windows 11 KB5083631 (feature/fixes) while KB5083769 causes third‑party backup failures; RDP warning display,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
3ed3340641197e60f493bd2fc17f59e26b442ee942b4805824d24d5f98769b63
Enrichment time
2026-05-02T19:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ConsentFix v3 attacks target Azure with automated OAuth abuse · Baitaphish