Multi-factor authentication is meant to stop stolen-password attacks. A newly documented phishing technique instead persuades users to approve a real Microsoft sign-in, allowing attackers to take over the resulting Microsoft 365 session without directly stealing credentials. The campaign abuses the OAuth device-code flow, a feature intended for devices such as smart TVs and meeting-room systems that cannot easily display a normal login page. Attackers send a code through a convincing document-sharing or account-verification lure, then wait for the victim to enter it on Microsoft’s genuine sign-in page. Trend Micro said in a report shared with Cyber Security News (CSN) that the technique turns a legitimate convenience feature...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!