LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
phishing

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...]

zeroday.news ·

Microsoft has issued a warning regarding a series of passkey-themed phishing attacks that have led to the compromise of corporate Microsoft accounts and the theft of data from Microsoft 365 services. The activity, observed since May 2026, involves threat actors linked to various extortion gangs, including those tracked by Microsoft as Storm-3121 and Storm-3032, and by Google Threat Intelligence as UNC6671.

The attacks begin with extensive pre-attack research into targeted organizations and employees, often leveraging public sources like social networking platforms. Attackers then impersonate corporate IT help desks, contacting victims via phone calls or SMS messages to their personal devices. They instruct employees to urgently update passkey, multi-factor authentication (MFA), or single sign-on (SSO) configurations to prevent loss of system access.

Victims are directed to sophisticated phishing sites designed to mimic legitimate Microsoft login pages. While the lures frequently mention passkeys, the attackers are not attempting to enroll a passkey. Instead, they use these themes to trick employees into signing into adversary-in-the-middle (AiTM) phishing sites or to authorize access via device-code authentication flows. AiTM attacks capture credentials and session tokens, while device-code phishing convinces victims to authorize an attacker-controlled client through Microsoft's legitimate authentication pages, granting access without further MFA challenges.

Phishing domains registered by the attackers often combine company names with terms like "passkey," "SSO," "key synchronization," and "identity verification." Examples include `passkeyhelpdesk[.]com`, `secure-passkey[.]com`, `setupmypasskey[.]com`, `add-passkey[.]com`, `integratedsso[.]com`, `oktasession[.]com`, `keysyncos[.]com`, and `oskeysync[.]com`. These often incorporate the victim company's name as a subdomain (e.g., `company-name.secure-passkey[.]com`) to enhance credibility.

Microsoft attributes the initial access activity to multiple threat actors within the same extortion ecosystem. Storm-3121 is associated with ShinyHunters and Falcon extortion, while Storm-3032 is believed to be linked to former BlackFile extortion group members now operating under the Helix name. This activity aligns with previous reports from Google Threat Intelligence concerning UNC6671, which Google has also connected to extortion groups like BlackFile, Helix, Falcon, Pink, and Redact.

Once an account is compromised, attackers establish a valid session, often from an unmanaged device, and immediately begin reconnaissance. Microsoft observed suspicious sign-ins to Microsoft 365 services, identified in Entra logs as "OfficeHome," associated with the Office 365 portal's shared infrastructure. Within minutes, the attackers access "My Apps," "My Profile," Microsoft Approval Management, account-management interfaces, and "My Sign-Ins" to enumerate accessible resources.

Further post-compromise activity includes accessing SharePoint Online, Outlook Web, Microsoft 365 collaboration and search services, internal business applications, and virtual desktop authentication flows. Attackers then establish persistence by adding their own MFA methods, such as new phone numbers, authenticator applications, or software-based one-time password tokens, allowing them to bypass future MFA challenges. This persistence, however, does not survive a complete credential and session reset.

Attackers extensively use Microsoft Graph to enumerate the cloud environment, querying for organizations, licenses, enabled services, users, groups, directory roles, privileged accounts, registered authentication methods, applications, service principals, OAuth permissions, application role assignments, SharePoint sites, document libraries, folders, files, OneDrive resources, mail folders, messages, and attachments. While individual Graph requests like `/users` or `/groups` are common, suspicious activity is indicated when the same account, application, or access token rapidly moves across different resources, checks privileges and authentication settings, and then accesses email, attachments, files, or documents.

Following reconnaissance, attackers proceed to data exfiltration from Microsoft 365. Microsoft observed high-volume access and download activity targeting Microsoft SharePoint Online and Microsoft OneDrive for Business, with some intrusions extending into Microsoft Exchange Online via REST API-based access to email content. This activity generates significant volumes of `FileAccessed` and `FileDownloaded` events, indicating systematic retrieval of cloud-hosted documents and organizational data.

The data theft appears automated, with connections often using the `python-httpx` user agent during SharePoint and OneDrive access. Attackers avoid rapid "smash-and-grab" exfiltration to evade detection, instead spreading data theft over several hours to multiple days, accessing fewer than 1,000 files or emails per hour to blend with legitimate traffic.

Microsoft advises organizations to monitor for unusual sign-ins followed by new MFA registrations, Microsoft Graph reconnaissance, and suspicious access to SharePoint, OneDrive, or Exchange. In the event of a compromise, administrators should revoke active sessions and tokens, reset credentials, remove any attacker-added authentication methods or mailbox rules, and require users to re-register their authentication methods.

phishing
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.