Research traces cloud compromises to fake passkey setup requests that trick users into authorizing attacker access and ...
A new phishing kit abuses a legitimate Microsoft device authorization flow intended for use with printers or smart TVs to steal authentication tokens, register attacker-controlled devices and gain ...
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single ...
Important changes are coming to multi-factor authentication (MFA) options for Brock University students, faculty and staff.
Microsoft's DCU seized EvilTokens infrastructure, a PhaaS platform that bypassed MFA at over 10,000 organizations using OAuth ...
Coinbase and Microsoft dismantled EvilTokens, an AI-driven phishing platform that compromised 12,000 inboxes across 79 countries, tracing $1.1M ...
Microsoft has made significant strides by taking down EvilTokens, a dangerous subscription service that exploited over 12,000 ...
Microsoft is warning organizations about an active social engineering campaign in which attackers impersonate IT help desks and use fake passkey setup requests to compromise employee identities and ...
A recently patched SharePoint flaw could give attackers a way to run code on vulnerable servers, and new research shows how it can be combined with authentication weaknesses to launch an attack ...
Microsoft disrupted EvilTokens after it was linked to more than 12,000 compromised inboxes across over 10,000 organizations.
In an active social engineering campaign, attackers are impersonating IT help desks and using fake passkey setup requests to compromise employee identities and gain access to enterprise cloud data.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results