CoPhish: Using Microsoft Copilot Studio as a wrapper for OAuth phishing

0
11

Copilot Studio links look benign, but they can host content to redirect users to arbitrary URLs. In this post, we document a method by which a Copilot Studio agent’s login settings can redirect a user to any URL, including an OAuth consent attack. – Read more