Close Menu
Must Have Gadgets –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Dreame’s X40 Ultra is arguably the best robovac deal you can grab for Black Friday

    November 27, 2025

    These Fire Stick and VPN Black Friday deals are a match made in heaven

    November 27, 2025

    Dell Black Friday Laptop Deals

    November 27, 2025
    Facebook X (Twitter) Instagram
    Must Have Gadgets –
    Trending
    • Dreame’s X40 Ultra is arguably the best robovac deal you can grab for Black Friday
    • These Fire Stick and VPN Black Friday deals are a match made in heaven
    • Dell Black Friday Laptop Deals
    • I Spy the Arlo Pro 6 Security Camera at an All-Time Low Price for Black Friday
    • Apple’s M4 Mac Mini Drops to Unbelievable Price of $479, Save 20%
    • Up to 83% Off on These Black Friday VPN Deals: Get Private Browsing From Anywhere
    • This Thanksgiving’s real drama may be Michael Burry versus Nvidia
    • The Ray-Ban Meta smart glasses are at their best-ever price for Black Friday
    • Home
    • Shop
      • Earbuds & Headphones
      • Smartwatches
      • Mobile Accessories
      • Smart Home Devices
      • Laptops & Tablets
    • Gadget Reviews
    • How-To Guides
    • Mobile Accessories
    • Smart Devices
    • More
      • Top Deals
      • Smart Home
      • Tech News
      • Trending Tech
    Facebook X (Twitter) Instagram
    Must Have Gadgets –
    Home»Mobile Accessories»Experts warn Microsoft Copilot Studio agents are being hijacked to steal OAuth tokens
    Mobile Accessories

    Experts warn Microsoft Copilot Studio agents are being hijacked to steal OAuth tokens

    adminBy adminOctober 27, 2025No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Experts warn Microsoft Copilot Studio agents are being hijacked to steal OAuth tokens
    Share
    Facebook Twitter LinkedIn Pinterest Email

    • CoPhish uses Copilot Studio agents to phish OAuth tokens via fake login flows
    • Attackers exploit Microsoft domains to appear legitimate and access sensitive user data
    • Mitigations include restricting app consent, enforcing MFA, and monitoring OAuth activity

    Security researchers from Datadog Security Labs are warning about a new phishing technique weaponizing Microsoft Copilot Studio agents to steal OAuth tokens and grants attackers access to sensitive information in emails, chats, calendars, and more.

    The technique is named CoPhish, and while Microsoft confirmed it is a social engineering technique, it acknowledged it and said it will work on addressing it.

    Here is how it works: an attacker can build, or share, a Copilot Studio agent (called “Topic”), whose user interface includes a “Login” or consent flow. If a victim clicks on the button, the flow will request Microsoft Entra/OAuth permissions. By approving the request, the victim essentially hands over OAuth tokens to attackers, which can then use them to access mail, chat, calendar, files, and automation capabilities inside the victim’s tenant.


    You may like

    Addressing through product updates

    The technique is particularly dangerous, Datadog stressed, because the agents are using legitimate Microsoft domains (copilotstudio.microsoft.com). This, together with the agent UI, could make the victim believe its authenticity, and lower their guard.

    Microsoft has acknowledged the potential for abuse and confirmed it would be working on addressing it: “We’ve investigated this report and are taking action to address it through future product updates,” a spokesperson said.

    “While this technique relies on social engineering, we remain committed to hardening our governance and consent experiences and are evaluating additional safeguards to help organizations prevent misuse.”

    If you are worried about being targeted this way, there are immediate mitigations to apply which can reduce risk. That includes restricting third-party app consent (requires admin consent), enforcing conditional access and MFA, blocking (or closely reviewing) Copilot Studio shared and published agents, monitoring unusual app registrations and granted OAuth tokens, and revoking suspicious tokens and apps.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    Via BleepingComputer

    Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

    And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

    The best antivirus for all budgets

    Our top picks, based on real-world testing and comparisons

    Agents Copilot experts hijacked Microsoft OAuth steal Studio tokens warn
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    admin
    • Website

    Related Posts

    Apple’s M4 Mac Mini Drops to Unbelievable Price of $479, Save 20%

    November 27, 2025

    The Apple Watch Series 11 42mm Cell Is $60 Off

    November 27, 2025

    Crypto hoarders dump tokens as shares tumble

    November 27, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Dreame’s X40 Ultra is arguably the best robovac deal you can grab for Black Friday

    November 27, 2025

    PayPal’s blockchain partner accidentally minted $300 trillion in stablecoins

    October 16, 2025

    The best AirPods deals for October 2025

    October 16, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    How-To Guides

    How to Disable Some or All AI Features on your Samsung Galaxy Phone

    By adminOctober 16, 20250
    Gadget Reviews

    PayPal’s blockchain partner accidentally minted $300 trillion in stablecoins

    By adminOctober 16, 20250
    Smart Devices

    The best AirPods deals for October 2025

    By adminOctober 16, 20250

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Latest Post

    Dreame’s X40 Ultra is arguably the best robovac deal you can grab for Black Friday

    November 27, 2025

    These Fire Stick and VPN Black Friday deals are a match made in heaven

    November 27, 2025

    Dell Black Friday Laptop Deals

    November 27, 2025
    Recent Posts
    • Dreame’s X40 Ultra is arguably the best robovac deal you can grab for Black Friday
    • These Fire Stick and VPN Black Friday deals are a match made in heaven
    • Dell Black Friday Laptop Deals
    • I Spy the Arlo Pro 6 Security Camera at an All-Time Low Price for Black Friday
    • Apple’s M4 Mac Mini Drops to Unbelievable Price of $479, Save 20%

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 must-have-gadgets.

    Type above and press Enter to search. Press Esc to cancel.