Microsoft phishing exploits trusted login flow
India, July 30 -- Cybercriminals are changing how phishing attacks work, making them much harder to detect. A recent Microsoft phishing campaign no longer relies on fake login pages. Instead, attackers use Microsoft's legitimate authentication process, allowing malicious emails to blend into normal business workflows and bypass many of the warning signs employees have been trained to spot.
Researchers identified more than 200 phishing emails sent between June 25 and the second week of July, targeting users across around 120 organizations worldwide. The emails impersonated Microsoft Teams task notifications from HR and encouraged recipients to sign in through a genuine Microsoft login page. Once authenticated, users were asked to approve...
Click here to read full article from source
To read the full article or to get the complete feed from this publication, please
Contact Us.