chiprook
← Security
SecuritySeptember 18, 2026, 22:00

Fake passkey setup requests lead to Microsoft 365 compromises

Microsoft Security Research linked cloud account compromises to attacks in which criminals call employees posing as IT support and ask them to update a passkey or sign-in settings. Attacks tracked since May: hackers added their own authentication methods, explored resources via Microsoft Graph and downloaded files from SharePoint and OneDrive, sometimes accessing Exchange Online mail.

Fake passkey setup requests lead to Microsoft 365 compromises
#Microsoft#Microsoft365#SharePoint#OneDrive
Read next
Security

Plugin4Shell: one git trick bypassed safety locks on four AI coding agents

Security

Tetragon in AWS CodeBuild blocks npm postinstall network access

Security

Kaspersky uncovers malware campaign spread via movie torrents

Security

Z.ai silently uploaded devs' local data: 313MB and 564 upload attempts