Coinbase phishing hijacks Microsoft 365 accounts via OAuth app

A new phishing marketing campaign utilizes a Coinbase-themed e mail pretending to be a “New terms of services” that prompts consumers to install an Office 365 consent application that presents attackers entry to a victim’s email.