Cybercriminals Exploit Microsoft Entra Passkey System to Breach Corporate Accounts
PremiumThreat group O UNC 066 uses phone-based phishing to trick employees into registering attacker-controlled Entra passkeys to hijack accounts.
§Topic · Identity, Access & Credentials
Credential theft, infostealers, session hijacking, MFA bypass, SSO and Active Directory attacks.
All dispatchesWriteOut session isolation bug in Writer AI could leak session tokens across tenants enabling full account takeover.
BusySnake infostealer used by 'Armored Likho' reached government agencies and electrical power entities, targeting critical infrastructure.
China-linked actors used a Roundcube exploit chain to compromise university physics and engineering departments and harvest credentials.
OAuth token theft in Klue supply chain enables access to Salesforce data; investigation ongoing.
Russian IAB-led campaign exploits FortiGate devices to harvest over 110 million credentials; high-risk for enterprises deploying Fortinet gear.
Spyder and MaXSS flaws in AI-powered Chrome extensions enable session hijacks and data access.
Fortinet credential theft campaign impacts half of internet-facing Firewalls and VPNs; urgency to rotate creds and patch exposed devices.
Get these articles delivered to your inbox.
Subscribe free