The OAuth2 phish is a relevant example of adversary adaptation. Not only is there no need to compromise credentials, but touted security measures such as MFA are also bypassed. It is users themselves who unwittingly approve malicious access to their data. If users fail to act, it will be up to domain administrators to spot and deal with any suspicious applications their users might have misguidedly approved. Visit Cofenses Remote Work Phishing Infocenter to stay up to date as threats evolve.”]
Source: https://cofense.com/mfa-bypass-phish-caught-oauth2-grants-access-user-data-without-password/

