Recent identity-based attacks have exploited vulnerabilities in authentication systems, targeting credentials and identity infrastructure. Notable incidents include the compromise of over 18,000 routers by APT28 to…
A sophisticated phishing campaign has been identified that routes victims through Google services, including Google Meet and Google Ads, before landing on a credential-harvesting page for Microsoft 365. This method…
A recently disclosed technique allows malware running in a Windows user session to exploit Windows Hello for Business (WHFB) keys to authenticate to Microsoft Entra ID. This method enables attackers to gain access…
Microsoft is updating Entra ID to allow Windows Hello for Business (WHfB) and macOS Platform Single Sign-On (PSSO) to serve as standalone multifactor authentication (MFA) methods. This change will eliminate the need for…