Tag

Sso

All articles tagged with #sso

Health Sector Faces Surge of ShinyHunters Data Theft via SSO Breaches
security1 day ago

Health Sector Faces Surge of ShinyHunters Data Theft via SSO Breaches

Health-ISAC warns that ShinyHunters are increasingly targeting healthcare by chaining supply-chain and identity attacks to gain access to cloud services through compromised SSO (Okta, Microsoft Entra, Google). Attackers use live voice phishing (vishing) to persuade employees or helpdesk staff to reset credentials or MFA, enabling rapid exfiltration from connected SaaS apps like Salesforce, Microsoft 365 and SharePoint. The advisory urges breaking the attack chain with out-of-band verification for resets, phishing-resistant MFA (FIDO2/WebAuthn), disabling SMS/voice OTP, treating SSO as Tier 0, centralizing SaaS logs, restricting API tokens, and rapid session revocation. Incidents have involved organizations such as Medtronic, DentaQuest, iRhythm, and OneMedical, and healthcare entities should focus on containment and strengthening controls over the next 30–60 days.

Device-code phishing with vishing redefines MFA in Microsoft Entra
security5 months ago

Device-code phishing with vishing redefines MFA in Microsoft Entra

Threat actors are abusing the OAuth 2.0 device authorization flow combined with voice phishing to hijack Microsoft Entra accounts. By using legitimate Microsoft OAuth client IDs, they trick victims into authenticating on microsoft.com/devicelogin, after which they can grab refresh tokens and issue access tokens, effectively bypassing MFA and accessing the victim's SaaS apps and data. Campaigns have targeted technology, manufacturing, and financial firms and may involve the ShinyHunters group. Security responses include revoking suspicious OAuth consents, auditing device-code sign-in events, disabling device-code flow when not needed, and enforcing conditional access policies to limit exposure.