Tag: CoPhish


  • CoPhish attack steals OAuth tokens through Microsoft Copilot Studio agents

    Cybersecurity researchers have uncovered a new phishing campaign called CoPhish, which abuses Microsoft Copilot Studio agents to steal OAuth tokens. The attack leverages legitimate Microsoft infrastructure, making it difficult to detect or block through traditional security filters. The CoPhish attack OAuth tokens campaign primarily targets Microsoft 365 users. By creating convincing Copilot agents within Microsoft’s…