SUBSCRIBE
Tech Journal Now
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
Reading: OAuth phishers make ‘check where the link points’ advice ineffective – Computerworld
Share
Tech Journal NowTech Journal Now
Font ResizerAa
  • News
  • Reviews
  • Guides
  • AI
  • Best Buy
  • Games
  • Software
Search
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Tech Journal Now > Software > OAuth phishers make ‘check where the link points’ advice ineffective – Computerworld
Software

OAuth phishers make ‘check where the link points’ advice ineffective – Computerworld

News Room
Last updated: March 3, 2026 2:29 pm
News Room
Share
1 Min Read
SHARE

How the attack works

The attack starts with a phishing email, with observed lures impersonating e-signature requests, HR communications, Microsoft Teams meeting invites, and password reset alerts, the malicious links embedded either in the email body or inside a PDF attachment, Microsoft researchers wrote in the blog post.

The link points to a real OAuth authorization endpoint but is built with deliberately broken parameters. Attackers use a “prompt=none” value, requesting a silent authentication with no login screen, and pair it with an invalid scope value. The combination is designed to fail. When it does, the identity provider redirects the user’s browser to a URI registered by the attacker.

“Although this behavior is standards-compliant, adversaries can abuse it to redirect users through trusted authorization endpoints to attacker-controlled destinations,” the researchers wrote in the blog post.

Read the full article here

You Might Also Like

Exploit available for new Chrome zero-day vulnerability, says Google

Your instant Android annoyance eliminator – Computerworld

Google Workspace tips and tutorials – Computerworld

Microsoft rolls out emergency fix for Windows 11 – Computerworld

A guide to the updates – Computerworld

Share This Article
Facebook Twitter Email Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Trending Stories

News

Filing: IPIC closing movie theater near Seattle, will lay off 64 workers amid bankruptcy

March 3, 2026
Games

Send us your wildest gaming clips from GTA 5 and you could win a $100 Steam gift card

March 3, 2026
News

Seattle’s newest early stage fund makes a bet on vertical AI startups

March 3, 2026
Games

World of Warcraft: Midnight players found an empty campsite that references 2019’s planet-hopping puzzler Outer Wilds

March 3, 2026
News

Seattle ranked best city to live in U.S. — right as tech leaders threaten to leave over taxes

March 3, 2026
Games

‘Half the fans would want to hang me’: Leon Kennedy’s voice actor won’t say whether he’s Team Ada or Team Claire, but he does point to all that Ada has done for Leon

March 3, 2026

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

Follow US on Social Media

Facebook Youtube Steam Twitch Unity

2024 © Prices.com LLC. All Rights Reserved.

Tech Journal Now

Quick Links

  • Privacy Policy
  • Terms of use
  • For Advertisers
  • Contact
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?