/?pid=sophisticated-phishing-surge-bypasses-microsoft-365-mfa-in-2026-26076

Updated:03:11 AM EDT May 08


this is ggmania.com subsite Sophisticated Phishing Surge Bypasses Microsoft 365 MFA in 2026 - TechAmok

Sophisticated Phishing Surge Bypasses Microsoft 365 MFA in 2026 - [security]
02:57 AM EDT - Apr,01 2026 - post a comment

KnowBe4 Threat Labs is tracking a sharp rise in OAuth device code phishing attacks targeting Microsoft 365 accounts across North America. Attackers send urgent emails mimicking document-signing requests or authenticator updates, redirecting victims through cloud services like AWS S3 and Cloudflare to a fake page that displays a device code. Users are then tricked into visiting the legitimate microsoft.com/devicelogin portal and entering the code, granting attackers persistent OAuth tokens without stealing passwords or bypassing MFA directly. This "living off the cloud" tactic provides ongoing access to emails, files, and collaboration tools. Organizations should block listed IOCs, train staff on device code risks, and monitor for suspicious OAuth consents to defend against the campaign.

Short overview of recent news articles

Linux 'Dirty Frag' Bug Lets Hackers Gain Root Access (May,08 2026 )

New 'Google Health' App to Replace Google Fit and Fitbit (May,08 2026 )

Apple has held early-stage discussions with Intel and Samsung about (May,07 2026 )

Chrome 148 Drops Massive 127-Vuln Patch - Update Now! (May,07 2026 )

iOS 26.5 Public Beta Delivers Battery Relief for iPhone Users (May,06 2026 )

Apple Reaches $250 Settlement for Failing to Deliver AI Siri as (May,06 2026 )

Anthropic pays $750K/ year per senior engineer. (May,05 2026 )

DDR6 RAM Heads for 2028 Launch with Blazing 17.6 GT/s Speeds (May,05 2026 )

HP Remotely Disables Printers Over Cancelled Ink Subscriptions (May,05 2026 )

Daemon Tools Hacked in Supply Chain Attack (May,05 2026 )

Japanese LEGO Genius Builds Accurate Working Clock (May,03 2026 )

Shakira's 2 million person Copacabana concert tonight: completely (May,03 2026 )

Headline: AT&T Insider Warns: Scammers Hijacking Phone Numbers to (May,03 2026 )

Syncthing: Free Open-Source Tool Ditches Paid Cloud Storage (May,02 2026 )

Your SIM Card Is a Silent Spy: How It Tracks Your Every Move-And Why (May,01 2026 )

RAMageddon Hits Apple: Tim Cook Warns of Soaring Memory Costs in (May,01 2026 )

Windows 11 Update Breaks Third-Party Backups (May,01 2026 )

Chrome's Critical Flaw: RCE Attacks Loom as Google Patches 30 (Apr,29 2026 )

PS5 Hack Unlocks Full Linux, Turns Console into a PC (Apr,29 2026 )

NVIDIA Releases New GeForce 596.36 WHQL Game Ready Drivers (Apr,28 2026 )

Valve Steam Controller Review | Latency Benchmarks, Battery Life, (Apr,28 2026 )

Microsoft Unleashes Autonomous Copilot Agent in Outlook (Apr,28 2026 )

Claude Cowork's 40 Secret Commands: Viral Thread Turns AI Assistant (Apr,27 2026 )

Drivechain Architect Paul Sztorc Unveils August Bitcoin Hard Fork (Apr,27 2026 )

Robinhood Phishing Scam Bypasses All Email Security Checks (Apr,27 2026 )

The Year of Windows Humiliation (Apr,26 2026 )

CIH 'Chernobyl' Virus Turns 27: The BIOS-Killer That Bricked (Apr,26 2026 )

AMD Under Fire for Alleged Reviewer Blacklist as Ryzen 9 9950X3D2 (Apr,25 2026 )

NEVER touch these BIOS settings... Unless you want to ruin your PC! (Apr,24 2026 )

Microsoft Lets Enterprise Admins Uninstall Copilot (Apr,24 2026 )

Claude Desktop Secretly Hooks Into Your Browsers (Apr,23 2026 )

AI Uncovers 271 Zero-Days in Firefox (Apr,22 2026 )

Microsoft Faces $2.8B UK Class-Action Lawsuit Over Cloud Licensing (Apr,22 2026 )

A USER SET A $10 BUDGET ALERT, WOKE UP TO A $25,672 GOOGLE CLOUD (Apr,22 2026 )

Over 1,370 SharePoint Servers Exposed to Active Spoofing Attacks (Apr,22 2026 )

Thunderbird 150 Released with Encrypted Search and OpenPGP (Apr,22 2026 )

Microsoft Supercharges OneDrive with AI and Smarter Sync (Apr,21 2026 )

Arbitrum Security Council Recovers $71M from KelpDAO Exploit (Apr,21 2026 )

Microsoft Rushes Emergency Fixes for Windows Server Chaos (Apr,20 2026 )

NSA Defies Pentagon Ban on Anthropic's Mythos AI (Apr,20 2026 )

Your Phone Is Now a Satellite Phone (Apr,19 2026 )

Aave Liquidity Crisis: $6B Drained After $290M KelpDAO Exploit (Apr,19 2026 )

RAVE Token Crashes 95% Amid Insider Manipulation Allegation (Apr,19 2026 )

Apple's M5 Mac Mini and Mac Studio Set for Imminent Launch with (Apr,18 2026 )

Anthropic Unleashes Claude Design: AI-Powered Visuals in Seconds (Apr,18 2026 )

Hit Old TP-Link Routers with Mirai Botnet Malware (Apr,17 2026 )

April Patches Trigger Reboot Hell on Windows Servers (Apr,17 2026 )

Fake Ledgers Hide Evil Inside: Seeds Stolen in Seconds (Apr,17 2026 )

GeForce 596.21 WHQL Game Ready Drivers (Apr,16 2026 )

Amazon Gets Serious About Satellite Service for Phones with Purchase (Apr,16 2026 )

>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs