logo

#ShadyHacks with Kyle Hanslovan

ID: 133507be-5910-5a3d-99d0-90a5d1b36bf7

STIX ID: report--133507be-5910-5a3d-99d0-90a5d1b36bf7

Feed Name: Huntress Blog

Date Published: 2025-11-26

Date Updated: 2026-04-28

...
...

The report demonstrates how attackers abuse identity-focused techniques to compromise Microsoft 365 without exploits or malware, starting with dark web credentials, phishing with ClickFix to steal session tokens, and session hijacking to bypass MFA; once inside, they establish persistence with inbox rules, move laterally via Teams, and reset passwords for non-SSO apps. It concludes with layered defenses including MFA with conditional access, auditing risky apps/inbox rules, strengthening email authentication (DMARC/DKIM/BIMI), incident response processes, and security awareness training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.