Microsoft says attackers are using fake passkey, MFA and SSO prompts to compromise cloud identities, add their own ...
Microsoft is warning organizations about an active social engineering campaign in which attackers impersonate IT help desks and use fake passkey setup requests to compromise employee identities and ...
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts ...
EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners ...
Research traces cloud compromises to fake passkey setup requests that trick users into authorizing attacker access and ...
Attackers use social engineering, calling personal phones, to steal Microsoft 365 access and pull SharePoint and OneDrive data.
Microsoft has outlined several mitigations to protect against attacks on multi-factor authentication that will unfortunately make life more difficult for your remote workers. Three years ago, attacks ...
A new phishing kit abuses a legitimate Microsoft device authorization flow intended for use with printers or smart TVs to steal authentication tokens, register attacker-controlled devices and gain ...
CVE-2026-69843 — a CVSS 10.0 unauthenticated bypass by spoofing — joins four other Microsoft authentication flaws since ...
Phishing-resistant MFA is now available on Linux desktops through the Microsoft identity broker. The feature supports Ubuntu 24.04 and 26.04, as well as RHEL 8, 9, and 10, bringing Linux support in ...