A new phishing kit abuses a legitimate Microsoft device authorization flow intended for use with printers or smart TVs to steal authentication tokens, register attacker-controlled devices and gain ...
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, ...
Attackers use social engineering, calling personal phones, to steal Microsoft 365 access and pull SharePoint and OneDrive ...
Microsoft says threat actors posing as IT helpdesk staff are tricking employees into phishing and device-code attacks that ...
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single ...
Das N0va-Kit erbeutet trotz abgeschlossener MFA gültige Microsoft-Token. Betroffen sind vor allem Organisationen in Europa ...
Seit Mai 2026 beobachtet Microsoft Security Research Social-Engineering-Kampagnen, bei denen Angreifer das Thema Passkeys und Single Sign-On (SSO) als Vorwand nutzen, um Sicherheitsbarrieren zu ...
The activity, observed since May 2026, relies heavily on social engineering. Victims may receive a phone call, SMS message, or Microsoft ...
Microsoft is warning customers of two recent social engineering campaigns aimed at compromising Microsoft accounts to target cloud-based assets and directing fraudulent business transactions over ...
Microsoft, geçiş anahtarı temalı kimlik avı saldırılarının Microsoft 365 hesaplarını ele geçirerek SharePoint, OneDrive ve ...
Злоумышленники обходят MFA через AiTM и коды устройств, крадут токены и массово извлекают данные Microsoft 365.