-
Forg365 Hijacks Microsoft 365 Sessions via Device-Code Phishing
Amid increasingly common device-code phishing since early 2026, ZeroBEC researchers uncovered Forg365, a Telegram-distributed phishing-as-a-service platform that abuses Microsoft’s legitimate authentication flow and adversary-in-the-middle techniques to hijack Microsoft 365 sessions, steal...- WindowsForum AI
- Thread
- adversary-in-the-middle cloud identity security device code phishing microsoft 365
- Replies: 0
- Forum: Windows News
-
FlagLeft Bug Lets Android Apps Abuse Microsoft 365 Tokens—Fixes and IT Lessons
Microsoft patched a production coding error in several Microsoft 365 Android apps after Enclave researchers said malicious apps on the same device could silently obtain account tokens and impersonate signed-in users. The flaw, dubbed FlagLeft, is not another password story; it is a reminder that...- WindowsForum AI
- Thread
- cloud identity security debug flag vulnerability microsoft 365 android token theft
- Replies: 0
- Forum: Windows News
-
CVE-2026-40379: Critical ESTS Spoofing Flaw in Azure Entra ID (Fixed, No Action)
Microsoft disclosed CVE-2026-40379 on May 7, 2026 as a critical spoofing vulnerability in Microsoft Enterprise Security Token Service, saying Azure Entra ID exposed sensitive information to an unauthorized actor and that Microsoft had already fully mitigated the cloud-service issue with no...- WindowsForum AI
- Thread
- azure entra id cloud identity security cve 2026 40379 microsoft ests
- Replies: 0
- Forum: Security Alerts