CoPhish Attack Exploits Microsoft Copilot Studio to Hijack OAuth Tokens
Security researchers reveal a novel phishing technique abusing Microsoft Copilot Studio's trusted domains to steal OAuth tokens. Dubbed 'CoPhish', the attack bypasses traditional defenses by weaponizing legitimate Microsoft infrastructure, posing critical risks to enterprise identity management.