CoPhish Breach Uses Microsoft Copilot to Steal Tokens
A new phishing campaign, dubbed CoPhish, exploits Microsoft Copilot Studio to steal OAuth tokens by mimicking legitimate Microsoft services. The CoPhish breach uses Microsoft Copilot’s customizable AI agents hosted on trusted domains to disguise malicious OAuth consent attacks, increasing the likelihood that users will approve harmful app permissions. According to Datadog Security Labs, attackers build […]
