Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
New ConsentFix Attack Let Attackers Hijack Microsoft Accounts by Leveraging Azure CLI

New ConsentFix Attack Let Attackers Hijack Microsoft Accounts by Leveraging Azure CLI

Posted on December 12, 2025December 12, 2025 By CWS

A classy new phishing assault approach referred to as “ConsentFix” that mixes OAuth consent phishing with ClickFix-style prompts to compromise Microsoft accounts with out requiring passwords or multi-factor authentication.

The assault leverages the Azure CLI app to realize unauthorized entry to sufferer accounts.

The ConsentFix assault operates solely inside the browser context, making it troublesome for conventional safety instruments to detect.

If a private e mail deal with is used, a enterprise deal with is prompted

Victims are directed to malicious or compromised web sites by Google Search outcomes.

These websites comprise a pretend Cloudflare Turnstile verification that collects e mail addresses and filters for focused organizations.

As soon as a qualifying e mail is entered, victims are prompted to click on a “Signal In” button that opens a professional Microsoft login web page in a brand new tab.

If customers are already logged into their Microsoft account, they choose their account from a dropdown menu.

The browser then redirects to a localhost URL containing an OAuth authorization code related to the sufferer’s Microsoft account.

The sufferer is instructed to repeat this localhost URL and paste it again into the phishing web page.

enable entry by URL

This straightforward copy-paste motion grants the attacker full entry to the sufferer’s Microsoft account through Azure CLI.

Successfully circumventing all password-based safety measures and phishing-resistant authentication like passkeys.

Why Azure CLI Is Susceptible

Azure CLI is a first-party Microsoft utility implicitly trusted in Entra ID and exempt from commonplace OAuth consent necessities.

In contrast to third-party purposes, Azure CLI can request permissions with out administrative approval and can’t be blocked or deleted.

This makes it a super goal for exploitation. The marketing campaign employs subtle detection evasion strategies, together with conditional email-based focusing on.

displaying the response URL and redirect

Synchronized IP blocking throughout a number of compromised websites and selective JavaScript loading based mostly on customer IP addresses.

These methods stop safety evaluation, making the assault practically unattainable to determine solely by URL-based checks.

 professional Microsoft web page and is redirected to a localhost URL containing a code related to their Microsoft account

PushSecurity urges organizations to observe Microsoft Azure CLI login occasions, which ought to sometimes be restricted to system directors and builders. Any uncommon interactive Azure CLI logins needs to be investigated.

Safety groups must also allow and monitor AADGraphActivityLogs to detect suspicious Azure AD enumeration exercise and look ahead to non-interactive logins from surprising geographic places.

Observe us on Google Information, LinkedIn, and X for every day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Accounts, Attack, Attackers, Azure, CLI, ConsentFix, Hijack, Leveraging, Microsoft

Post navigation

Previous Post: NANOREMOTE Malware Leverages  Google Drive API for Command-and-Control (C2) to Attack Windows Systems
Next Post: MITRE Releases 2025 List of Top 25 Most Dangerous Software Vulnerabilities

Related Posts

Ransomware Actors Primarily Targeting Retailers This Holiday Season to Deploy Malicious Payloads Ransomware Actors Primarily Targeting Retailers This Holiday Season to Deploy Malicious Payloads Cyber Security News
GitLab Releases Critical Security Updates to Fix Vulnerabilities GitLab Releases Critical Security Updates to Fix Vulnerabilities Cyber Security News
Telegram CEO Faces Terrorism Charges from Russia Telegram CEO Faces Terrorism Charges from Russia Cyber Security News
Hackers Actively Exploiting 7-Zip RCE Vulnerability in the Wild Hackers Actively Exploiting 7-Zip RCE Vulnerability in the Wild Cyber Security News
Checkpoint Details on How Attackers Drained 8M from Balancer Pools Within 30 Minutes Checkpoint Details on How Attackers Drained $128M from Balancer Pools Within 30 Minutes Cyber Security News
Fake Chrome Extension Mimics TronLink, Steals Crypto Data Fake Chrome Extension Mimics TronLink, Steals Crypto Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles
  • Critical Vulnerability in Oracle PeopleSoft Exploited Globally
  • Kiteworks Recommends Nine-Hour System Shutdown Amid Cyber Threat
  • New Botnet x47.c Leverages AI for Advanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark