{
  "$type": "site.standard.document",
  "bskyPostRef": {
    "cid": "bafyreievnfqf7mokhs7pujtu7cfoyaw3txg6f6lk2olfwnnwq4gehbqliy",
    "uri": "at://did:plc:6wtxqaikjf62unmnajbfbq5v/app.bsky.feed.post/3mg7hbzcqecd2"
  },
  "coverImage": {
    "$type": "blob",
    "ref": {
      "$link": "bafkreib5rvt5kt4g4odnrjc76dk4wgzclyerdp6sgoyikz4u3rkookxdue"
    },
    "mimeType": "image/webp",
    "size": 21242
  },
  "path": "/microsoft-warns-oauth-redirect-abuse-in-entra-id-can-power-phishing-and-malware-delivery/",
  "publishedAt": "2026-03-03T20:03:55.000Z",
  "site": "https://vpncentral.com",
  "tags": [
    "News",
    "Microsoft warns OAuth redirect abuse in Entra ID can power phishing and malware delivery",
    "VPN Central"
  ],
  "textContent": "Microsoft says attackers are abusing a normal OAuth redirect behavior in Microsoft Entra ID to send victims from trusted login pages to attacker-controlled sites. The technique does not steal OAuth tokens and does not break the OAuth standard. Instead, it forces an authorization error, then uses the redirect path to move the victim to a […]\n\nThe post Microsoft warns OAuth redirect abuse in Entra ID can power phishing and malware delivery appeared first on VPN Central.",
  "title": "Microsoft warns OAuth redirect abuse in Entra ID can power phishing and malware delivery"
}