Trusted Redirects: OAuth as a Phishing Handoff
The new Microsoft phishing problem is not just the fake login page. It is the trusted redirect that gets users there. OAuth prompts, consent screens, and legitimate identity-provider hops are now being used as a browser handoff into phishing and adversary-in-the-middle flows.