SUBSCRIBE
Tech Journal Now
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
  • More Articles
Reading: OAuth phishers make ‘check where the link points’ advice ineffective – Computerworld
Share
Tech Journal NowTech Journal Now
Font ResizerAa
  • News
  • Reviews
  • Guides
  • AI
  • Best Buy
  • Games
  • Software
Search
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
  • More Articles
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Tech Journal Now > Software > OAuth phishers make ‘check where the link points’ advice ineffective – Computerworld
Software

OAuth phishers make ‘check where the link points’ advice ineffective – Computerworld

News Room
Last updated: March 3, 2026 2:29 pm
News Room
Share
1 Min Read
SHARE

How the attack works

The attack starts with a phishing email, with observed lures impersonating e-signature requests, HR communications, Microsoft Teams meeting invites, and password reset alerts, the malicious links embedded either in the email body or inside a PDF attachment, Microsoft researchers wrote in the blog post.

The link points to a real OAuth authorization endpoint but is built with deliberately broken parameters. Attackers use a “prompt=none” value, requesting a silent authentication with no login screen, and pair it with an invalid scope value. The combination is designed to fail. When it does, the identity provider redirects the user’s browser to a URI registered by the attacker.

“Although this behavior is standards-compliant, adversaries can abuse it to redirect users through trusted authorization endpoints to attacker-controlled destinations,” the researchers wrote in the blog post.

Read the full article here

You Might Also Like

Apple plans to make Mac minis in the US – Computerworld

How to get started – Computerworld

World ID expands its ‘proof of human’ vision for the AI era – Computerworld

Here’s what $5,849 gets you in an M5 Max MacBook Pro – Computerworld

Apple announces the iPhone 17e and a new M4-powered iPad Air – Computerworld

Share This Article
Facebook Twitter Email Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Trending Stories

News

How a Seattle biotech pioneer’s long game paid off – GeekWire

April 22, 2026
Games

I’m sick of breaking the bank buying AAA releases, so I’ve hunted down overlooked alternatives to 2026’s biggest games

April 22, 2026
Games

Fallout: New Vegas dev says Bethesda made the studio sit through ‘a whole powerpoint about all the things Obsidian did wrong’

April 22, 2026
AI

Google Chat becomes an agent interface for Workspace – Computerworld

April 22, 2026
News

Brev raises $3.3M for AI agents that keep companies on track with goals – GeekWire

April 22, 2026
Games

Peter Molyneux’s right about one thing: It’s sad how no one seems to care about god games anymore

April 22, 2026

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

Follow US on Social Media

Facebook Youtube Steam Twitch Unity

2024 © Prices.com LLC. All Rights Reserved.

Tech Journal Now

Quick Links

  • Privacy Policy
  • Terms of use
  • For Advertisers
  • Contact
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?