You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cyber vigilance
About this tag
Cyber vigilance is critical in defending against sophisticated attacks like those from Russian threat actors UTA0352 and UTA0355, who exploit OAuth to compromise Microsoft 365 accounts of Ukraine-linked NGOs. This tag covers discussions on phishing campaigns, OAuth token abuse, and the importance of monitoring authentication flows to prevent unauthorized access. Topics include attack mechanics, threat actor tactics, and security measures for enterprise environments. Stay informed on emerging threats and best practices for maintaining cyber vigilance in Microsoft 365 and other platforms.
In a recent development, Russian threat actors identified as UTA0352 and UTA0355 have been targeting Ukraine-linked nongovernmental organizations (NGOs) by exploiting the OAuth protocol to compromise Microsoft 365 accounts.
The Mechanics of the Attack
The attackers initiated their campaign with...