A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials.
CloudSEK found 4,148 stolen session cookies and 1,032 plaintext passwords in an operation targeting 461 organizations across more than 40 countries.
Microsoft says attackers are using fake passkey, MFA and SSO prompts to compromise cloud identities, add their own ...
Sentire uncovers the GhostCode phishing kit abusing Microsoft OAuth to steal tokens, register attacker devices and access ...
Extortion gangs are using passkey and SSO phishing to hijack Microsoft accounts, steal tokens, and exfiltrate Microsoft 365 data.
Attackers guessed the password of a dormant account and were able to apply their own MFA to it - providing access to the victim's network.
Researchers demonstrate TrustSink, an Entra attack that uses rogue external MFA providers to capture passwords during normal ...
What if the very tools you rely on to secure your organization’s data are quietly becoming obsolete? That’s the reality facing businesses as Microsoft prepares to retire its legacy Multi-Factor ...
Microsoft 365 passkeys replace SMS MFA with secure cryptographic public-private key pairs. Configure Entra profiles and manage device rollouts.