Skip to main content
Security

Microsoft details passkey-themed cloud-account phishing campaigns

Microsoft details passkey-themed cloud-account phishing campaigns Image: Primary
Microsoft disclosed two campaigns that used third-party email delivery infrastructure and passkey-themed social engineering against enterprise accounts. In the cloud intrusions, attackers contacted employees by phone or message, directed them to counterfeit sign-in sites, then used adversary-in-the-middle or device-code authentication flows. Microsoft said compromised accounts were used for Microsoft Graph activity, mailbox collection, and SharePoint and OneDrive downloads; attackers also added authentication methods in some cases to retain access. The activity has been detected since May 2026 and affected multiple accounts.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security AI
Security AI

Vendor study finds AI-related SOC alerts up 685% but almost all noise

A security vendor's review of roughly 16.9 million enterprise SOC alerts found about 73,000, or 0.43%, were tied to AI tools and agents, with that volume up 685% between February and June 2026. The vendor sorted the AI-related al...

Security
Security

Dutch NCSC warns Check Point VPN flaws face imminent exploitation

The Dutch National Cyber Security Centre warned that exploitation of two critical Check Point VPN flaws is imminent and urged organizations to install available updates. CVE-2026-85102 involves improper certificate-data validation...