vimarsana.com


A savvy phishing campaign manages to evade native Microsoft security defenses, looking to steal O365 credentials.
A phishing campaign bent on stealing Microsoft login credentials is using Google Firebase to bypass email security measures in Microsoft Office 365, researchers said.
Researchers at Armorblox uncovered invoice-themed emails sent to at least 20,000 mailboxes that purport to share information about an electronic funds transfer (EFT) payment. The emails carry a fairly vanilla subject line, “TRANSFER OF PAYMENT NOTICE FOR INVOICE,” and contain a link to download an “invoice” from the cloud.
Clicking that link begins a series of redirects that eventually takes targets to a page with Microsoft Office branding that’s hosted on Google Firebase. That page is of course a phishing page, bent on harvesting Microsoft log-in information, secondary email addresses and phone numbers.

Related Keywords

Rajat Upadhyaya ,Google ,Microsoft Office ,Exchange Online Protection ,Microsoft ,Microsoft Defender For Office ,Google Firebase ,Spam Confidence Level ,Microsoft Defender ,Domain Based Message Authentication ,ராஜாத் உபாதியாய ,கூகிள் ,மைக்ரோசாஃப்ட் அலுவலகம் ,பரிமாற்றம் நிகழ்நிலை ப்ரொடெக்ஶந் ,மைக்ரோசாஃப்ட் ,மைக்ரோசாஃப்ட் பாதுகாவலர் க்கு அலுவலகம் ,ஸ்பேம் நம்பிக்கை நிலை ,மைக்ரோசாஃப்ட் பாதுகாவலர் ,களம் அடிப்படையிலானது செய்தி அங்கீகார ,

© 2025 Vimarsana

vimarsana.com © 2020. All Rights Reserved.