When legit is the trick: Phishing’s sneaky new moves.
ID: d8e7e4dc-e0ae-5d18-a078-e11b477fdd65
STIX ID: report--d8e7e4dc-e0ae-5d18-a078-e11b477fdd65
Feed Name: The CyberWire
Threat Score
*Executive summary:* This podcast episode outlines how attackers are increasingly abusing legitimate Microsoft workflows — notably device code phishing that tricks users into completing real OAuth logins (granting attackers valid access tokens) and Microsoft 365 Direct Send to make phishing emails appear to originate from inside organizations — reflecting a broader shift toward weaponizing built-in cloud services instead of relying on obviously malicious infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
