Security News The New Phishing Click: How OAuth Consent Bypasses MFA TheHackerNews Daniel Bender 19 May 2026 Share OAuth consent is the phishing vector MFA misses—long-lived tokens and cross-app access bypass trusted identity controls.