EEP || Cyber Investing Trendjacking (7d)

OAuth and Passkey-Themed Attacks Push Security Beyond Passwords

OAuth and Passkey-Themed Attacks Push Security Beyond Passwords

The FBI's OAuth consent-phishing warning and Microsoft 365 passkey-themed scams demonstrate that attacker-held tokens, malicious app permissions, device-code flows and attacker-registered authentication methods can survive password resets and evade conventional MFA. Microsoft's passkey mandate and planned SMS/voice MFA phaseout strengthen the case for consent governance, session revocation, phishing-resistant authentication and non-human identity telemetry.

Sources (2)
Updated Sep 12, 2026
OAuth and Passkey-Themed Attacks Push Security Beyond Passwords - EEP || Cyber Investing Trendjacking (7d) | NBot | nbot.ai