Passkey Lures, Stolen Sessions, and the Microsoft 365 Data Trail
Microsoft describes intrusions that start with fake passkey support calls and continue through new MFA methods, Graph reconnaissance, and cloud data access.
14 articles
Microsoft describes intrusions that start with fake passkey support calls and continue through new MFA methods, Graph reconnaissance, and cloud data access.
We tear apart a realistic phishing email using Security Decoder — headers, URLs, JWT tokens, and obfuscated JavaScript — and show exactly what each red flag means.
A fake Cloudflare CAPTCHA campaign used npm packages and mirror CDNs as trusted-looking web hosting. The packages were not the payload; the mirror URLs were.
A domain that looks pixel-perfect in your browser's address bar can still be fake. Here's how homograph and Punycode phishing exploits Unicode lookalike characters — and how to catch it.
BEC caused $3.05 billion in reported US losses in 2025 alone — without a single exploit. Here's the full attack chain from mailbox compromise to wire fraud, and the controls that actually stop it.
Meta's Muse Image turns public Instagram content into promptable visual context. The security issue is not novelty; it is lower-friction impersonation at social-media scale.
WhatsApp usernames reduce phone-number exposure, but they also create a new global namespace where brands, public bodies, and lookalike handles can become fraud infrastructure.
Attackers do not always need your password. A single OAuth consent grant can give a malicious or compromised app durable access to mail, files, calendars, and SaaS data.
Scammers are abusing legitimate notification systems from Microsoft, Google, PayPal, Docusign, and other trusted platforms. The message can pass SPF, DKIM, and DMARC because the platform really sent it.
Adversary-in-the-Middle phishing silently proxies real login pages and steals session tokens — making MFA useless. Here's how it works and how to detect it.
Browser-in-the-Browser (BitB) attacks forge convincing browser popup windows using pure HTML and CSS — making phishing pages nearly impossible to spot by eye. Here's how it works and how to defend against it.
MFA is no longer enough to protect Microsoft Entra ID accounts. Attackers steal tokens, register their own devices, and bypass Conditional Access — without ever touching a password. Here's the full attack chain and how to detect it.
Windows .lnk shortcut files can show one target while silently executing another. Discover five spoofing techniques including CVE-2025-9491, how attackers exploit them, and how to detect them.
A step-by-step debrief of a real-world red team engagement — from passive OSINT through AiTM phishing, EDR evasion, and ADCS exploitation to full domain compromise. What worked, what didn't, and what would have stopped us.