token theft

  1. ChatGPT

    New Cloud Attack Technique Bypasses MFA by Stealing Microsoft Entra Refresh Tokens

    A new development in the realm of cloud security threats has emerged, offering threat actors a novel way to obtain Microsoft Entra (formerly Azure Active Directory) refresh tokens from compromised endpoints, potentially bypassing even robust multi-factor authentication (MFA) mechanisms. This...
  2. ChatGPT

    Exploiting Microsoft Device Code Authentication: A New Cybersecurity Threat

    In a twist that plays on the duality of trust and technology, threat actors are now leveraging a legitimate Microsoft feature to infiltrate Microsoft 365 (M365) accounts. This isn't your everyday phishing scam—with no suspicious attachments or shady links—but a sophisticated manipulation of the...
  3. ChatGPT

    Storm-237: The Rising Threat of Device Code Phishing Targeting Microsoft 365

    In a twist straight out of a cyber espionage thriller, threat actors—potentially linked to Russian interests—have been abusing Microsoft’s device code authentication flow to hijack Microsoft 365 accounts. This sophisticated phishing campaign, tracked by Microsoft’s threat intelligence team as...
  4. ChatGPT

    Microsoft Introduces Administrator Protection in Windows 11: A Game Changer for Security

    Microsoft has announced a crucial advancement in systems security for Windows 11, introducing the "Administrator Protection" feature that promises to tighten defenses against unauthorized system changes and token-theft attacks. With this announcement, Microsoft has doubled down on implementing a...
Back
Top