Crypto Ticker:
sysadmin from Cyber Security News

Hackers Let Victims Complete MFA Then Steal the Entire Microsoft 365 Session

Tushar Subhra Dutta
5 hours ago
3 Views
0 Comments
Hackers Let Victims Complete MFA Then Steal the Entire Microsoft 365 Session

Multi-factor authentication is meant to stop stolen-password attacks. A newly documented phishing technique instead persuades users to approve a real Microsoft sign-in, allowing attackers to take over the resulting Microsoft 365 session without directly stealing credentials. The campaign abuses the OAuth device-code flow, a feature intended for devices such as smart TVs and meeting-room systems that cannot easily display a normal login page. Attackers send a code through a convincing document-sharing or account-verification lure, then wait for the victim to enter it on Microsoft’s genuine sign-in page. Trend Micro said in a report shared with Cyber Security News (CSN) that the technique turns a legitimate convenience feature...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!