Attackers abuse OAuth’s built-in redirects to launch phishing and malware attacks
Attackers abuse OAuth’s built-in redirects to launch phishing and malware attacks
Wed Mar 04 2026
IAM
Malware
Phishing
www.malwarebytes.com
Researchers have found that attackers are abusing OAuth to send users from legitimate Microsoft or Google login pages to phishing sites or malware downloads.