Threat actors are leveraging Graph API to identify lucrative targets, then passing their access to extortion groups like ...
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, ...
Attackers use social engineering, calling personal phones, to steal Microsoft 365 access and pull SharePoint and OneDrive ...
Узнайте, как хакеры используют Microsoft Graph API и Device Code Phishing для обхода MFA и массового скачивания данных из ...
Thunderbird bindet M365-Postfächer nativ über die Microsoft Graph API an. Das macht einen manuellen Wechsel für EWS-Konten nötig.
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single ...
Microsoft says threat actors posing as IT helpdesk staff are tricking employees into phishing and device-code attacks that ...
Microsoft details a million-email CEO fraud campaign and passkey-themed attacks that compromised cloud accounts and enabled ...
A new phishing kit abuses a legitimate Microsoft device authorization flow intended for use with printers or smart TVs to steal authentication tokens, register attacker-controlled devices and gain ...
I reverse-engineered an implant that runs C2 via a real OneDrive account and can remotely replace every stolen credential.
Microsoft のセキュリティ分析チームは2026年9月9日、複数のMicrosoft ...
On the investment side, Microsoft plans to more than triple its data center capacity to around 38 gigawatts by 2032 and is ...