You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
ngo cybersecurity
About this tag
This tag covers cybersecurity threats and best practices relevant to non-governmental organizations (NGOs), with a focus on Microsoft 365 security. The featured thread discusses OAuth phishing attacks, where cybercriminals exploit trust in Microsoft 365 to steal credentials and access sensitive data. NGOs, often operating with limited IT resources, are prime targets for such sophisticated phishing campaigns. The content highlights the importance of understanding modern phishing techniques, including OAuth consent grants, and implementing robust security measures like multi-factor authentication and conditional access policies. IT administrators and security professionals working with NGOs will find practical advice on defending against these evolving threats.
They say trust is the cornerstone of any relationship—especially if that relationship is between you, the internet, and a determined Russian adversary with a penchant for phishy invitations and suspicious requests for OAuth codes.
Phishing in the OAuth Era: New Tricks for Old Hackers
When we...