Next-Gen Phishing Tactics Users Aren't Ready For
Huntress, Friday, August 28th, 2026
Huntress covers ClickFix, browser-in-the-browser and OAuth consent phishing, tactics standard awareness training misses.
Huntress argues that standard security awareness training has focused for years on credential harvesting through fake login pages, while attacker tradecraft has moved on.
The post covers three techniques users are unprepared for: ClickFix, which tricks the victim into running attacker-supplied commands themselves; browser-in-the-browser attacks, which render a convincing fake authentication window inside a real page; and OAuth consent phishing, which obtains persistent account access without ever capturing a password.
Each defeats the mental model that phishing means a suspicious link to a fake login field. Huntress ties the discussion to training users with its Security Awareness Training product.