The New Phishing Click: How OAuth Consent Bypasses MFA
2026-05-19T13:24:08Z•75b4c247661a53fb580e32aee02d38e5c4fb687be51779cbfe43e3b750863954
active-exploitationcisa-kevcredential-theftgithub-actionsincident-responsemail-gatewaymfa-bypassmicrosoft-365node-ipcnpmoauth-consentphaaSphishingprivilege-escalationrcesupply-chain-attacktoken-theftvs-code-extensionweb-skimmingwindows-zero-day
What happened
A cluster of high-impact incidents and active-exploitation vulnerabilities were reported: the EvilTokens PhaaS is abusing OAuth consent/device login flows to bypass MFA and has compromised 340+ Microsoft 365 organizations; multiple supply-chain attacks (compromised Nx Console VS Code extension, GitHub Action tags moved to imposter commits, Mini Shai-Hulud and TanStack npm compromises, malicious node-ipc releases) are harvesting developer/CI secrets and deploying credential-stealers; critical product vulnerabilities are being actively exploited or added to KEV (Cisco Catalyst SD‑WAN auth bypass
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 75b4c247661a53fb580e32aee02d38e5c4fb687be51779cbfe43e3b750863954
- Enrichment time
- 2026-05-19T13:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.