{"success":true,"data":{"id":"consentfix-oauth-token-copy-paste","label":"ConsentFix OAuth harvest — instructs victim to copy post-login URL from browser into form (bypasses passkeys/MFA)","description":"Body instructs the recipient to sign in to Microsoft/Azure/Google, then copy the post-login URL from their browser address bar and paste it back into a form — the ConsentFix pattern disclosed by Push Security in December 2025. Harvests an OAuth authorization code without capturing password or MFA, and defeats phishing-resistant auth. Active against Azure CLI. Key fingerprint: \"copy the URL from your browser\" + \"localhost\" or \"127.0.0.1\" reference + OAuth CTA.","tier":"danger","category":"phishing","isThin":false}}