Executive Vishing Campaign Cracks Microsoft 365 with MFA Token Theft

TL;DR Summary
Threat actors impersonating IT desk staff use vishing and an adversary-in-the-middle token theft flow to harvest Microsoft 365 credentials and MFA approvals, enabling access to authenticated sessions via proxy replay; they exfiltrate data from SharePoint, OneDrive, Exchange, and Box, targeting executives across sectors. Defenses include phishing-resistant MFA, Conditional Access, restricting SharePoint data access, and employee training on vishing risks.
Reading Insights
Total Reads
1
Unique Readers
7
Time Saved
2 min
vs 3 min read
Condensed
88%
502 → 59 words
Want the full story? Read the original article
Read on The Hacker News