Tag

Mfa

All articles tagged with #mfa

Passkey phishing surge targets Microsoft 365 data in extortion-linked campaign
technology27 days ago

Passkey phishing surge targets Microsoft 365 data in extortion-linked campaign

Microsoft warns that extortion-linked groups are using passkey- and SSO-themed social engineering (AiTM and device-code phishing) to compromise Microsoft 365 accounts, perform reconnaissance with Microsoft Graph, and exfiltrate data from SharePoint Online and OneDrive over hours to days, often registering convincing phishing domains and adding attacker-controlled authentication methods; defenders should deploy phishing-resistant MFA, revoke sessions, reset credentials, remove attacker-added methods, and restrict sensitive cloud resources to managed devices.

Executive Vishing Campaign Cracks Microsoft 365 with MFA Token Theft
technology1 month ago

Executive Vishing Campaign Cracks Microsoft 365 with MFA Token Theft

Threat actors impersonating IT desk staff use vishing and an adversary-in-the-middle token theft flow to harvest Microsoft 365 credentials and MFA approvals, enabling access to authenticated sessions via proxy replay; they exfiltrate data from SharePoint, OneDrive, Exchange, and Box, targeting executives across sectors. Defenses include phishing-resistant MFA, Conditional Access, restricting SharePoint data access, and employee training on vishing risks.

Entra ID Makes Passkeys the Default, Ditching SMS/Voice MFA by 2027
technology2 months ago

Entra ID Makes Passkeys the Default, Ditching SMS/Voice MFA by 2027

Microsoft will make passkeys the default authentication method for Entra ID starting September 2026, auto-enabling them for users currently on SMS/voice MFA; SMS/voice authentication will be retired across all tenants on February 1, 2027. Users already using passkeys, Windows Hello for Business, FIDO2 keys, or other phishing-resistant methods can continue. After rollout, organizations should ensure all users adopt phishing-resistant methods to avoid sign-in disruptions, with third-party telecom providers available via the Security Store if needed. Microsoft cites AI-enabled phishing risks and says passkeys reduce credential theft by replacing phishable factors.

Massive Azure CLI credential spray uses legacy flow to bypass MFA, hits 78 accounts
security3 months ago

Massive Azure CLI credential spray uses legacy flow to bypass MFA, hits 78 accounts

Security researchers warn of a large-scale, automated password-spray against Microsoft Azure CLI that logged over 81 million login attempts and compromised at least 78 Microsoft accounts across 64 organizations. The attackers used the deprecated OAuth 2.0 Resource Owner Password Credentials (ROPC) flow to bypass Conditional Access policies, targeting credentials from breached lists and exploiting MFA configurations that didn’t cover Azure CLI logins. The activity originated largely from an IPv6 range linked to LSHIY LLC (AS32167). Recommendations include enforcing MFA for all users and apps, restricting the Azure CLI app to non-admins, and ensuring CAPs are fully configured to close gaps exposed by ROPC.

Kali365 Phishing Kit Bypasses MFA to Target Microsoft 365 Accounts
technology3 months ago

Kali365 Phishing Kit Bypasses MFA to Target Microsoft 365 Accounts

The FBI warns of Kali365, a phishing-as-a-service kit that bypasses multi-factor authentication by tricking victims into approving a device-code sign-in, enabling attackers to harvest OAuth tokens and access Outlook, Teams, and OneDrive; security guidance includes never entering unsolicited device codes, navigating directly to Microsoft rather than using links, monitoring sign-ins and devices, revoking suspicious sessions, keeping MFA enabled, and reporting incidents.

FortiBleed Breach Exposes 86K FortiGate Devices in Global Credential Campaign
security3 months ago

FortiBleed Breach Exposes 86K FortiGate Devices in Global Credential Campaign

CISA warns Fortinet customers about FortiBleed, a global credential-stuffing and brute-force campaign targeting internet-facing FortiGate firewalls and VPN gateways, with 86,644 devices compromised as of June 19, 2026. The attack, attributed to Russian-speaking actors, proceeds in two steps: scanning for exposed Fortinet endpoints, then using leaked or organization credentials to gain access, before passively harvesting more credentials. Sectors most affected include telecom, government, and education, with the U.K. NCSC calling it a worldwide campaign; many admins’ passwords remain SHA-256-hashed from older FortiGate versions, though PBKDF2 hashing is used in newer FortiOS releases. Fortinet maintains the incident data likely comes from prior breaches and brute-forcing, not a current advisory. CISA recommends terminating active sessions, resetting passwords on internet-facing systems, enforcing PBKDF2, applying strong password policies, enabling phishing-resistant MFA, reviewing logs, and reducing attack surfaces to mitigate risk.

Microsoft mends MFA and My Sign-Ins outage, restores access after cache-triggered failover
technology4 months ago

Microsoft mends MFA and My Sign-Ins outage, restores access after cache-triggered failover

Microsoft fixed an outage that prevented MFA setup and access to My Sign-Ins (504 errors). It mitigated by failing over to alternate infrastructure and is monitoring service health; an update later blamed a recent cache configuration change for the failover and high resource usage during EU traffic, with mitigation rolled back and traffic restored to the original infrastructure.

MuddyWater Uses Teams to Harvest Credentials and Subvert MFA in Chaos False-Flag Campaign
cybersecurity5 months ago

MuddyWater Uses Teams to Harvest Credentials and Subvert MFA in Chaos False-Flag Campaign

Security researchers describe a MuddyWater operation that exploited Microsoft Teams for external contact and screen-sharing to harvest user credentials (credentials.txt/cred.txt) and push MFA changes, followed by backdoor access using DWAgent and AnyDesk. The attackers deployed a custom RAT (Game.exe) and used C2 domains linked to MuddyWater, framing the intrusion as a Chaos ransomware false-flag campaign focused on credential theft and data exfiltration rather than encryption. The campaign featured indicators like a forged code-signing certificate and stolen credentials enabling lateral movement to Domain Controllers.

OAuth Redirect Attacks Deliver Malware and Bypass MFA
security7 months ago

OAuth Redirect Attacks Deliver Malware and Bypass MFA

Microsoft Defender researchers warn attackers abuse OAuth 2.0 redirect flows to bypass phishing protections by registering malicious OAuth apps and directing users to attacker-controlled redirect URIs, sometimes via PDFs; victims are taken to phishing pages or intermediaries like EvilProxy that can intercept session cookies to bypass MFA. Other campaigns deliver ZIPs with LNK files that launch PowerShell and DLL side-loading to drop payloads. These are identity-based threats exploiting standard OAuth error handling; Microsoft advises tighter OAuth permissions, stronger identity protections, Conditional Access, and cross-domain detection across email, identity, and endpoints.

"Ticketmaster Data Breach Exposes Millions, Sparks Lawsuits"
cybersecurity2 years ago

"Ticketmaster Data Breach Exposes Millions, Sparks Lawsuits"

Ticketmaster and several other Snowflake customers have been hacked, with threat actors obtaining credentials through info-stealing malware or purchasing them online. The hacking group ShinyHunters has claimed responsibility, seeking large sums for the stolen data. The breaches highlight the importance of multifactor authentication (MFA), which was not in place for the compromised accounts. Snowflake and security firms Mandiant and Crowdstrike are investigating, with no evidence yet of a vulnerability in Snowflake's platform.