Microsoft is retiring native SMS and voice authentication for Microsoft Entra ID workforce tenants, with a hard cutoff on February 1, 2027. Passkeys are now the default authentication method, and users without alternative methods will face mandatory registration prompts to avoid sign-in lockouts.
Microsoft warns that extortion-linked groups are using passkey- and SSO-themed social engineering (AiTM and device-code phishing) to compromise Microsoft 365 accounts, perform reconnaissance with Microsoft Graph, and exfiltrate data from SharePoint Online and OneDrive over hours to days, often registering convincing phishing domains and adding attacker-controlled authentication methods; defenders should deploy phishing-resistant MFA, revoke sessions, reset credentials, remove attacker-added methods, and restrict sensitive cloud resources to managed devices.
Threat actors impersonating IT desk staff use vishing and an adversary-in-the-middle token theft flow to harvest Microsoft 365 credentials and MFA approvals, enabling access to authenticated sessions via proxy replay; they exfiltrate data from SharePoint, OneDrive, Exchange, and Box, targeting executives across sectors. Defenses include phishing-resistant MFA, Conditional Access, restricting SharePoint data access, and employee training on vishing risks.
Microsoft will make passkeys the default authentication method for Entra ID starting September 2026, auto-enabling them for users currently on SMS/voice MFA; SMS/voice authentication will be retired across all tenants on February 1, 2027. Users already using passkeys, Windows Hello for Business, FIDO2 keys, or other phishing-resistant methods can continue. After rollout, organizations should ensure all users adopt phishing-resistant methods to avoid sign-in disruptions, with third-party telecom providers available via the Security Store if needed. Microsoft cites AI-enabled phishing risks and says passkeys reduce credential theft by replacing phishable factors.
Security researchers warn of a large-scale, automated password-spray against Microsoft Azure CLI that logged over 81 million login attempts and compromised at least 78 Microsoft accounts across 64 organizations. The attackers used the deprecated OAuth 2.0 Resource Owner Password Credentials (ROPC) flow to bypass Conditional Access policies, targeting credentials from breached lists and exploiting MFA configurations that didn’t cover Azure CLI logins. The activity originated largely from an IPv6 range linked to LSHIY LLC (AS32167). Recommendations include enforcing MFA for all users and apps, restricting the Azure CLI app to non-admins, and ensuring CAPs are fully configured to close gaps exposed by ROPC.
The FBI warns of Kali365, a phishing-as-a-service kit that bypasses multi-factor authentication by tricking victims into approving a device-code sign-in, enabling attackers to harvest OAuth tokens and access Outlook, Teams, and OneDrive; security guidance includes never entering unsolicited device codes, navigating directly to Microsoft rather than using links, monitoring sign-ins and devices, revoking suspicious sessions, keeping MFA enabled, and reporting incidents.
CISA warns Fortinet customers about FortiBleed, a global credential-stuffing and brute-force campaign targeting internet-facing FortiGate firewalls and VPN gateways, with 86,644 devices compromised as of June 19, 2026. The attack, attributed to Russian-speaking actors, proceeds in two steps: scanning for exposed Fortinet endpoints, then using leaked or organization credentials to gain access, before passively harvesting more credentials. Sectors most affected include telecom, government, and education, with the U.K. NCSC calling it a worldwide campaign; many admins’ passwords remain SHA-256-hashed from older FortiGate versions, though PBKDF2 hashing is used in newer FortiOS releases. Fortinet maintains the incident data likely comes from prior breaches and brute-forcing, not a current advisory. CISA recommends terminating active sessions, resetting passwords on internet-facing systems, enforcing PBKDF2, applying strong password policies, enabling phishing-resistant MFA, reviewing logs, and reducing attack surfaces to mitigate risk.
Microsoft fixed an outage that prevented MFA setup and access to My Sign-Ins (504 errors). It mitigated by failing over to alternate infrastructure and is monitoring service health; an update later blamed a recent cache configuration change for the failover and high resource usage during EU traffic, with mitigation rolled back and traffic restored to the original infrastructure.
Security researchers describe a MuddyWater operation that exploited Microsoft Teams for external contact and screen-sharing to harvest user credentials (credentials.txt/cred.txt) and push MFA changes, followed by backdoor access using DWAgent and AnyDesk. The attackers deployed a custom RAT (Game.exe) and used C2 domains linked to MuddyWater, framing the intrusion as a Chaos ransomware false-flag campaign focused on credential theft and data exfiltration rather than encryption. The campaign featured indicators like a forged code-signing certificate and stolen credentials enabling lateral movement to Domain Controllers.
CISA urged U.S. organizations to harden Microsoft Intune following Stryker's breach, recommending least-privilege admin access, MFA, RBAC, and multi-admin approvals to prevent the wipe of nearly 80,000 devices.
CISA urges U.S. organizations to harden endpoint-management configurations after the Stryker breach, calling for least-privilege RBAC, phishing-resistant MFA, Entra ID/Conditional Access, and Multi Admin Approval, with guidance drawn from Microsoft Intune best practices to prevent abuse of legitimate endpoint-management tools.
Microsoft Defender researchers warn attackers abuse OAuth 2.0 redirect flows to bypass phishing protections by registering malicious OAuth apps and directing users to attacker-controlled redirect URIs, sometimes via PDFs; victims are taken to phishing pages or intermediaries like EvilProxy that can intercept session cookies to bypass MFA. Other campaigns deliver ZIPs with LNK files that launch PowerShell and DLL side-loading to drop payloads. These are identity-based threats exploiting standard OAuth error handling; Microsoft advises tighter OAuth permissions, stronger identity protections, Conditional Access, and cross-domain detection across email, identity, and endpoints.
The Valorant 11.09 update introduces mandatory multi-factor authentication for certain accounts to combat smurfs, along with quality-of-life improvements and numerous bug fixes across maps and agents.
Microsoft is investigating ongoing authentication issues affecting Microsoft 365 users, caused by a recent change aimed at improving MFA sign-in functionality. The incident impacts users in various regions, with Microsoft working on configuration updates to mitigate the problem while seeking a long-term solution.
Ticketmaster and several other Snowflake customers have been hacked, with threat actors obtaining credentials through info-stealing malware or purchasing them online. The hacking group ShinyHunters has claimed responsibility, seeking large sums for the stolen data. The breaches highlight the importance of multifactor authentication (MFA), which was not in place for the compromised accounts. Snowflake and security firms Mandiant and Crowdstrike are investigating, with no evidence yet of a vulnerability in Snowflake's platform.