Stay alert: How hackers bypass verification to steal credentials — common tactics and key defenses.
Neowin reports that Microsoft Defender security researchers recently uncovered a malicious campaign ...
Neowin reports that Microsoft Defender security researchers recently uncovered a malicious campaign targeting energy companies. The attackers used an Adversary-in-the-Middle (AiTM) technique to steal employee credentials and bypass multi-factor authentication (MFA).
According to the report, the operation often starts with a “seed” or “patient-zero” account. Attackers use social engineering to compromise one employee account, then leverage it to access additional internal mailboxes, harvest credentials, and expand laterally—ultimately enabling MFA bypass.
Next, the compromised account is used to send phishing emails at scale, disguised as SharePoint document-sharing notifications. Victims who click the link are redirected to a spoofed site that prompts them to enter usernames and passwords. Critically, attackers also steal session cookies—tokens that maintain an authenticated session—allowing them to reuse the session even when MFA is enabled.
After gaining access to multiple legitimate accounts, attackers create inbox rules to auto-delete incoming mail and mark messages as “read,” reducing the chances of detection. They then propagate the attack by emailing contacts in the victim’s address book—reportedly up to 600 phishing emails per victim—to drive chained spread.
To further cover tracks, the attackers monitor compromised inboxes and delete bounce-back messages and “out-of-office” auto-replies. If recipients become suspicious and ask questions, the attackers may impersonate the victim to respond that everything is normal, then delete the conversation afterward.
Microsoft advised impacted organizations to revoke all session cookies, remove attacker-created mailbox rules, and check for unauthorized changes to MFA settings. The company emphasized that simply resetting passwords is not sufficient in this scenario.
Trump’s U-Turn: Escalating Military Aid as Russia-Ukraine Conflict Stalls
According to CNN, the situation in the Russia-Ukraine conflict has shifted dramatically in the past ...
Trump’s “Silent 48 Hours”: Inside the Fed’s Rate Cut Drama and How Powell Secured an 11–1 Victory for Independence
This week, the Federal Reserve delivered its first rate cut of the year, trimming rates by 25 basis ...
The Must-Eat Autumn Fruit: 21 Times More Vitamin C Than Apples, Supports Digestion, Weight Loss & Blood Sugar Control
As the cool autumn breeze arrives, it’s the perfect time to enjoy seasonal fruits. Among them, kiwif...
Atour Hotels Offers Hidden Camera Detector for Guests
On December 3, some netizens shared their experiences using hidden camera detectors at Atour Hotels,...
Sun Yingsha Wins While Resting! China’s Team Claims 6 World Titles, Yingsha Secures 4 Crowns, Doha Withdrawal Likely Due to Asian Cup
Despite suffering a left ankle injury, Sun Yingsha did not join Shenzhen University in Nanjing for t...
Rockets Hit Hard! Steven Adams Out Indefinitely with Severe Ankle Injury
On January 21, Houston Rockets center Steven Adams was ruled out indefinitely with a grade 3 left an...
Chinese Entrepreneurs in South Africa Are Striking Gold in E-Commerce
Are South Africa’s New Middle Class Being “Claimed” by Chinese Entrepreneurs? Chinese business owner...
Has Taemin’s Appearance Changed After Leaving SM? Latest Photos Reveal an Unexpected Twist
(Seoul, March 29) Taemin of SHINee has been making headlines following a major career move. After si...
Three goals ruled out in one game! Oscar fails to recreate the “Hand of God”, Kuai Jiwen denied first CSL goal
In Round 4 of the 2026 Chinese Super League, Shanghai Port hosted Yunnan Yukun in a match dominated ...
Xiang Zuo's Livestream with Brother Xiang You Sparks Concern Over His On-Camera Demeanour
(Beijing, July 25) Chinese actor Xiang Zuo recently appeared in a livestream sales event alongside h...