None
EN
Phishing attacks don’t look fake anymore: Watch for these 7 scams
['More This Author', '.Wp-Block-Co-Authors-Plus-Coauthors.Is-Layout-Flow', 'Class', 'Wp-Block-Co-Authors-Plus', 'Display Inline', '.Wp-Block-Co-Authors-Plus-Avatar', 'Where Img', 'Height Auto Max-Width', 'Vertical-Align Bottom .Wp-Block-Co-Authors-Plus-Coauthors.Is-Layout-Flow .Wp-Block-Co-Authors-Plus-Avatar', 'Vertical-Align Middle .Wp-Block-Co-Authors-Plus-Avatar Is .Alignleft .Alignright']
PCWorld
Microsoft 365 login trap circumvents two-factor authenticationA new attack method uses the genuine Microsoft login dialog and therefore requires almost no fake websites.
To do this, the criminals use the OAuth device code flow.
The criminals send their victims a phishing message, claiming that the victim’s device needs to be re-authorized to log in to their Microsoft 365 account.
To do this, they combine genuine Microsoft authentication pages with phishing websites.
ProofpointThese are genuine Microsoft notifications and web pages.