OAuth token theft surges as attackers weaponise consent
Account takeover is now perpetrated by hijacking trusted workflows, even in environments where multi-factor authentication is switched on.
We haven't written up this one. ITWeb has the full story — the link below goes straight to it.