Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single ...
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, ...
Windows Report on MSN
Microsoft 365 accounts are being hijacked through fake passkey alerts
Extortion gangs are using passkey and SSO phishing to hijack Microsoft accounts, steal tokens, and exfiltrate Microsoft 365 ...
Microsoft is warning organizations about an active social engineering campaign in which attackers impersonate IT help desks and use fake passkey setup requests to compromise employee identities and ...
Research traces cloud compromises to fake passkey setup requests that trick users into authorizing attacker access and ...
A new phishing kit abuses a legitimate Microsoft device authorization flow intended for use with printers or smart TVs to steal authentication tokens, register attacker-controlled devices and gain ...
Threat actors are leveraging Graph API to identify lucrative targets, then passing their access to extortion groups like ...
Microsoft says threat actors posing as IT helpdesk staff are tricking employees into phishing and device-code attacks that ...
Microsoft warns of fake passkey and IT support attacks targeting Microsoft 365 accounts to steal authentication tokens and access corporate cloud data.
Attackers use social engineering, calling personal phones, to steal Microsoft 365 access and pull SharePoint and OneDrive ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results