ConsentFix: MFA-Bypassing OAuth Phishing
ConsentFix lets attackers hijack Microsoft's own OAuth sign-in flow to steal authorization codes and bypass MFA entirely. Researchers link the technique with moderate-to-high confidence to Russia's APT29.