Money-grubbing crooks abuse OAuth – and baffling absence of MFA – to do financial crimes
ID: a3d52a3b-d981-53ab-b13d-1991f41e0b0c
STIX ID: report--a3d52a3b-d981-53ab-b13d-1991f41e0b0c
Feed Name: The Register (Security)
Microsoft warns that criminals are abusing OAuth 2.0 by using compromised accounts to create malicious OAuth applications and grant them permissions, enabling large-scale spam campaigns, phishing (including token-stealing proxies), BEC reconnaissance, and deployment of Azure VMs for illicit crypto-mining that has resulted in significant cloud costs; Microsoft recommends enforcing MFA, conditional access, continuous access evaluation, monitoring VM creation and app-consent activity, and provides incident response playbooks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
