BreachFeed
company

Microsoft

Tracked by 3 people · Cloud Provider

Track Microsoft

Incident history

Cyber Security News·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvloevx1crvhmu2jj9a3bbw

Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers

A new phishing campaign is moving fake login pages into victims’ browsers. Rather than sending people to a malicious website, its operators use browser-generated blob URLs to assemble the page in local memory, leaving less for security tools to inspect before it appears. The operation starts with a DocuSign-themed email carrying a calendar invitation. Its […] The post Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers appeared first on Cyber Security…

Cyber Security News·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvk6ejo1b24hmu2t9s86cqz

Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data

Hackers are using passkey-themed phishing to take control of Microsoft 365 accounts and collect cloud data. It can defeat MFA protections. The campaign starts with calls and texts to employees. Attackers pose as IT support, claim a passkey, MFA, or single sign-on setting needs attention, and direct targets to lookalike sign-in pages. Compromised accounts can […] The post Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data appeared first on Cyber Security…

Cyber Security News·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujpe6s05efhmu2ih24qb21

Hackers Chain Chrome and Windows Zero-Days in New BlueMoon Exploit Kit Attacks

Multiple espionage-motivated threat actors have rapidly adopted a newly discovered exploit kit that chains Chrome browser and Microsoft Windows vulnerabilities to deploy backdoors and surveillance tools against government, defense, and commercial targets worldwide. Security researchers at Proofpoint have named the kit “BlueMoon,” identifying its use by at least four distinct threat clusters since late August […] The post Hackers Chain Chrome and Windows Zero-Days in New BlueMoon Exploit Kit…

The Hacker News·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtuik8k104b5hmu26bgcvv4u

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujpe6s05emhmu2vejfu6rp

Microsoft Expands Windows Family Safety With Built-In Age Verification and Parental Controls

Microsoft is expanding Windows Family Safety with account-based age verification, privacy-focused age signals, and improved parental controls. The company said the updates are designed to help Windows apps, games, services, and AI experiences provide protections that match a user’s age. The initiative uses the Microsoft account as the central identity layer for family safety on […] The post Microsoft Expands Windows Family Safety With Built-In Age Verification and Parental Controls appeared…