CyberHighPartialAccelerating
7.3
Threat actors exploit BYOD voice calls to breach Microsoft 365, target corporate data
Dark ReadingLO·2 days ago
Microsoft reports threat actors tied to ShinyHunters, Helix, and other extortion groups are using passkey and SSO-themed social engineering to compromise corporate Microsoft accounts and exfiltrate data from Microsoft 365. The attack exploits user trust in passkey adoption, a novel vector. This signals an escalation in credential-based attacks against cloud services, with potential for widespread data breaches.
Entities