Kryptovaluta-ticker:
sysadmin fra Cyber Security News

Hackers Let Victims Complete MFA Then Steal the Entire Microsoft 365 Session

Tushar Subhra Dutta
5 hours ago
6 Visninger
0 Kommentarer
Hackers Let Victims Complete MFA Then Steal the Entire Microsoft 365 Session

Multi-factor authentication is meant to stop stolen-password attacks. A newly documented phishing technique instead persuades users to approve a real Microsoft sign-in, allowing attackers to take over the resulting Microsoft 365 session without directly stealing credentials. The campaign abuses the OAuth device-code flow, a feature intended for devices such as smart TVs and meeting-room systems that cannot easily display a normal login page. Attackers send a code through a convincing document-sharing or account-verification lure, then wait for the victim to enter it on Microsoft’s genuine sign-in page. Trend Micro said in a report shared with Cyber Security News (CSN) that the technique turns a legitimate convenience feature...

Læs hele artiklen hos kilden.

Deltag i diskussionen — kommenter, stem og del links.

Registrer
Var dette nyttigt?
Del:

Kommentarer (0)

Log venligst ind eller opret dig for at deltage i diskussionen

Ingen kommentarer ennå. Bli den første til å kommentere!