Get a Pentest and security assessment of your IT network.

News

Phishing Attack Bypassed Office 365 Multifactor Protections

A recent phishing campaign bypassed multifactor authentication protections within Microsoft Office 365 to steal users’ credentials. The attack leveraged the OAuth2 framework and the OpenID Connect protocol, along with a malicious SharePoint link designed to trick a victim into granting permission to a rogue application that the hackers control. From there, the rogue app could begin harvesting data from the Office 365 files or the contact list, Cofense says. The phishing attack started with an email that contains a malicious link thats designed to look like a SharePoint file.”]

Source: https://www.cuinfosecurity.com/phishing-attack-bypassed-office-365-multifactor-protections-a-14310

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2