#ConsentFix
ConsentFix v3 attacks target Azure with automated OAuth abuse
ConsentFix v3 attacks target Azure with automated OAuth abuse
A new attack type, dubbed ConsentFix v3, has been circulating on hacker forums, building on the previous technique by adding automation and scaling potential.
www.bleepingcomputer.com
May 2, 2026 at 3:08 PM
A new variation of the ClickFix attack dubbed 'ConsentFix' abuses the Azure CLI OAuth app to hijack Microsoft accounts without the need for a password or to bypass multi-factor authentication (MFA) verifications.
New ConsentFix attack hijacks Microsoft accounts via Azure CLI
A new variation of the ClickFix attack dubbed 'ConsentFix' abuses the Azure CLI OAuth app to hijack Microsoft accounts without the need for a password or to bypass multi-factor authentication (MFA) verifications.
www.bleepingcomputer.com
December 11, 2025 at 3:11 PM
#ConsentFix is a great way for attackers to work around some protective layers but not all. @naunheim.cloud , @cbrhh.bsky.social and I wrote a blog post on detection and mitigations. Hope you find it useful and can adapt it to your environment.

www.glueckkanja.com/de/posts/202...
January 2, 2026 at 7:52 PM
Clickfix hits Windows and Mac users. One campaign used a sponsored X ad to lure Mac users; another, “ConsentFix,” hijacks Microsoft 365 accounts without malware.
Verified X ad spreads Mac malware, while ConsentFix steals Microsoft accounts
Two new campaigns show how cybercriminals are increasingly relying on social engineering instead of software exploits to compromise devices and accounts.
www.malwarebytes.com
July 3, 2026 at 2:18 PM
"'ConsentFix', a browser-based ClickFix-style attack with OAuth consent grants" ... leveraging the Azure CLI app client to social engineer for easy access into Entra ID 👀 I got nerdsniped by this, so I played with it a bit and tried a drag-and-drop gesture! Video: youtu.be/AAiiIY-Soak
December 13, 2025 at 2:00 PM
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
ConsentFix and ClickFix attacks steal Microsoft 365 tokens in seconds using fake prompts and OAuth flows. Learn how these MFA bypass tactics work and how to defend against them. [...]
www.bleepingcomputer.com
July 2, 2026 at 3:02 PM
ESET detections of #ClickFix doubled (+108%) between H2 2025 and H1 2026 as attackers expanded beyond fake CAPTCHAs to AI platforms (#AI-fix), browser extensions (#CrashFix), and cloud authentication workflows (#ConsentFix). 1/5
July 22, 2026 at 8:53 AM
Finally, ConsentFix targets OAuth authorization tokens instead of passwords. Victims are tricked into handing over tokens that can provide access to Microsoft accounts without the need for credential theft. 4/5
July 22, 2026 at 8:53 AM
-New ConsentFix attack
-Microsoft bug bounty expands to.... EVERYTHING [Gary Oldman voice]
-10k Docker Hub images leak secrets
-1k MCP servers exposed online
-SPAs leak 42k secrets
-We have an OWASP Agentic Top 10
-The 2025 CWE Top 25 is out
December 12, 2025 at 10:21 AM
ConsentFix:ClickFix攻撃のもう一つの亜種

サイバー犯罪者は、複雑なマルウェアから離れ、CAPTCHA、Cookieの同意、認証プロンプトといった無意味なデジタル儀式を無意識にクリックし続けるという、一般的なユーザーの習慣を悪用するソーシャルエンジニアリングにますます依存するようになっている。この習慣は、攻撃者が最近積極的に使用しているClickFixテクニックの様々な種類によってしばしば標的にされている。研究者たちは最近、このテクニックの新しい亜種を発見し、 ConsentFixと名付けた。これにより、攻撃者はOAuth(現在非常に人気のある攻撃手法)を介してMicr...
ConsentFix: a new ClickFix variation for compromising Microsoft 365 accounts
Discover how attackers use the ConsentFix attack to hijack Microsoft 365 sessions, what risks it poses to organizations, and how to protect your corporate infrastructure.
www.kaspersky.com
August 20, 2026 at 2:15 AM
ConsentFix(別名AuthCodeFix):OAuth2認証コードフィッシングの検出
#CybersecurityNews
blog.nviso.eu/2026/01/29/c...
ConsentFix (a.k.a. AuthCodeFix): Detecting OAuth2 Authorization Code Phishing
Walkthrough the ConsentFix (a.k.a. AuthCodeFix) attack mechanics, and learn about mitigations and detections strategies.
blog.nviso.eu
February 3, 2026 at 12:57 PM
the other day I learned about 'consentfix' and I just could not 🤦‍♂️
March 14, 2026 at 2:59 AM
ConsentFix debrief: Insights from the new OAuth phishing attack
ConsentFix debrief: Insights from the new OAuth phishing attack
ConsentFix is an OAuth phishing technique abusing browser-based authorization flows to hijack Microsoft accounts. Push Security shares new insights from continued tracking, community research, and evolving attacker techniques.
www.bleepingcomputer.com
January 14, 2026 at 4:55 PM
A new attack type, dubbed ConsentFix v3, has been circulating on hacker forums, building on the previous technique by adding automation and scaling potential.
ConsentFix v3 attacks target Azure with automated OAuth abuse
A new attack type, dubbed ConsentFix v3, has been circulating on hacker forums, building on the previous technique by adding automation and scaling potential.
www.bleepingcomputer.com
May 2, 2026 at 2:33 PM
New type of "Clickfix" attack (I'm quoted)

www.csoonline.com/article/4105...
Meet ConsentFix, a new twist on the ClickFix phishing attack
The attack tricks employees into creating a URL that lets hackers grab their Microsoft login tokens.
www.csoonline.com
December 12, 2025 at 1:19 PM
ConsentFix: OAuth 同意付与をハイジャックするブラウザネイティブの ClickFix スタイルの攻撃を分析
#CybersecurityNews
pushsecurity.com/blog/consent...
ConsentFix: Browser-native ClickFix hijacks OAuth grants
Analysing
pushsecurity.com
December 17, 2025 at 3:39 PM
ConsentFix y ClickFix: Cómo secuestran las cuentas de Microsoft 365 en 3 segundos

Vía: @bleepingcomputer.com
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
ConsentFix and ClickFix attacks steal Microsoft 365 tokens in seconds using fake prompts and OAuth flows. Learn how these MFA bypass tactics work and how to defend against them.
www.bleepingcomputer.com
July 3, 2026 at 1:47 AM
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds: www.bleepingcomputer.com/news/securit...
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
ConsentFix and ClickFix attacks steal Microsoft 365 tokens in seconds using fake prompts and OAuth flows. Learn how these MFA bypass tactics work and how to defend against them.
www.bleepingcomputer.com
July 2, 2026 at 11:24 PM
Meet ConsentFix, a new twist on the ClickFix phishing attack www.csoonline.com/article/4105...
Meet ConsentFix, a new twist on the ClickFix phishing attack
The attack tricks employees into creating a URL that lets hackers grab their Microsoft login tokens.
www.csoonline.com
December 14, 2025 at 11:12 AM