Don’t trust that app!

Don’t trust that app!

While our team is out on winter break, please enjoy this episode of Research Saturday. Today we are joined by ⁠⁠Selena Larson⁠⁠, co-host of ⁠⁠Only Malware in the Building⁠⁠ and Staff Threat Researcher and Lead Intelligence Analysis and Strategy at ⁠⁠Proofpoint⁠⁠, sharing their work on "Microsoft OAuth App Impersonation Campaign Leads to MFA Phishing." Proofpoint researchers have identified campaigns where threat actors use fake Microsoft OAuth apps to impersonate services like Adobe, DocuSign, and SharePoint, stealing credentials and bypassing MFA via attacker-in-the-middle phishing kits, mainly Tycoon. These attacks redirect users to fake Microsoft login pages to capture credentials, 2FA tokens, and session cookies, targeting nearly 3,000 Microsoft 365 accounts across 900 environments in 2025. Microsoft’s upcoming security changes and strengthened email, cloud, and web defenses, along with user education, are recommended to reduce these risks. The research can be found here: ⁠⁠⁠⁠Microsoft OAuth App Impersonation Campaign Leads to MFA Phishing

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(3742)

Let’s kill the kill switch.

Let’s kill the kill switch.

Could an AI kill switch create more problems than it solves? A critical Rails flaw is under active attack. Malicious browser extensions steal cryptocurrency. Fire Ant targets trusted network infrastru...

31 Aug 27min

CyberWire Daily at 10: A decade of emerging threat actors and APTs. [Special Edition]

CyberWire Daily at 10: A decade of emerging threat actors and APTs. [Special Edition]

In this episode, Maria Varmazis and Dave Bittner from N2K Cyberwire get back together to discuss the evolution of advanced persistent threats (APTs), threat actor landscape, attribution changes, and ...

30 Aug 24min

Who let the AI hack? [Research Saturday]

Who let the AI hack? [Research Saturday]

Today we are joined by Crystal Morin, Senior Cybersecurity Strategist, and Michael Clark, Senior Director of Threat Research, at Sysdig, sharing their work on "LLMjacking evolved: Attackers are using ...

29 Aug 23min

The blacklist boomerang.

The blacklist boomerang.

A judge rules the Trump administration illegally labeled Anthropic a national security risk. The White House moves to keep foreign technology out of U.S. power systems. OpenAI rallies a global cyber d...

28 Aug 29min

Meta gets a Meta-sized bill.

Meta gets a Meta-sized bill.

Meta settles. Australian police arrest two alleged TeamPCP members. The White House moves to shore up water utility cybersecurity. ATF reports a major cyber incident. The Navy tells sailors to lock do...

27 Aug 31min

The feds flip the script.

The feds flip the script.

The U.S. disrupts a Chinese hacking operation blamed for intrusions at several sensitive government agencies. CISA says more than 100 water systems were targeted in July. Attackers exploit a critical...

26 Aug 32min

CISA is running on empty.

CISA is running on empty.

Lawmakers request an investigation into cuts at CISA. Threat actors actively exploit a Zimbra Collaboration Suite vulnerability. A Chinese AI lab preps release of a powerful open-weight model. A new p...

25 Aug 28min

The odds were classified.

The odds were classified.

Polymarket traders win big on U.S. military insider information. Slovakia deactivates speed cameras with Russian backdoors. TikTok pays $400 million to settle kids' privacy allegations. Hackers infect...

24 Aug 30min

Populært innen Politikk og nyheter

aftenpodden
giver-og-gjengen-vg
forklart
popradet
aftenpodden-usa
stopp-verden
nokon-ma-ga
fotballpodden-2
det-store-bildet
lydartikler-fra-aftenposten
bt-dokumentar-2
dine-penger-pengeradet
hanna-de-heldige
rss-espen-lee-usensurert
rss-gukild-johaug
aftenbla-bla
rss-ness
e24-podden
frokostshowet-pa-p5
liverpoolno-pausepraten