Microsoft Warns of Phishing Attack 'Targeting Hundreds of Orgs'
Microsoft is warning of a new phishing attack that is abusing OAuth request links and “targeting hundreds of orgs.”
Stay updated with breaking news from Microsoft Security Intelligence Twitter. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Microsoft is warning of a new phishing attack that is abusing OAuth request links and “targeting hundreds of orgs.”
A phishing campaign is going on right now. It's meant to con Office 365 users into giving up their credentials. Microsoft says to watch out for it. Microsoft wants to alert you to a phishing scheme going on that involves the most classic of tricks, including barely misspelled domain names, URLs, and sender addresses. If you're hyper-vigilant of typos and tend to catch these things even when your spam filters fail to, you're all safe. But for everyone else who only takes a quick glance to verify whether an email is from a legitimate sender, Microsoft has a message: Look closer.
Microsoft is warning the aerospace and travel sectors of a new targeted attack campaign aimed at stealing sensitive information from affected companies. The tech giant said it had been tracking the “dynamic campaign” for several months via a series of spear-phishing emails designed to deliver an “actively developed loader.” The screenshot posted to Microsoft Security Intelligence Twitter feed was of a phishing email spoofing a legitimate organization and requesting a quote for a cargo charter. “An image posing as a PDF file contains an embedded link (typically abusing legitimate web...
A strain of ransomware called DearCry is being used to target unpatched Exchange servers. Microsoft has released patches for Exchange servers, but some organizations have not patched systems yet. Check Point Research reports that exploitation attempts doubled every 2-3 hours over a recent 24-hour period. While Microsoft has rolled out emergency patches to address vulnerabilities on its Exchange server software, many systems remain unpatched. Attackers are now increasingly going after unpatched systems. A strain of ransomware called DearCry is being utilized by attackers to target unpatched on...