Adversaries are skipping passwords: OAuth consent phishing & token theft are now top initial-access paths
Across recent incident response cases, the dominant initial-access vector is no longer password spray or basic phishing. Instead, adversaries are abusing OAuth application consent and token theft to...