Обложка канала

Sys-Admin & InfoSec Channel

Посты с ИТ-ресурсов, новости, тулзы, хакинг, администрирование, возможны бредовые посты с мемами, поздравлениями, может даже хейтами..

Sys-Admin & InfoSec Channel

3 года назад
Открыть в
AiTM/ MFA phishing attacks in combination with “new” Microsoft protections (2023 edition) MFA is not the end all solution to identity security challenges. With only MFA there is still a risk for more modern attacks (MFA fatique, AiTM, PRT, OAuth Attacks and more). Adversary-in-the-middle phishing attacks are still more common in use. Since the removal of basic authentication from Exchange Online more and more attackers are using more modern attacks like adversary-in-the-middle phishing, cookie theft, and other used attacks. What is AiTM, automatic attack disruption and etc: — jeffreyappel.nl/aitm-mf…2023-edt
AiTM/ MFA phishing attacks in combination with "new" Microsoft protections (2023 edition)

Adversary-in-the-middle phishing attacks are still more common in use. Since the removal of basic authentication from Exchange Online more and more attackers are using more modern attacks like adversary-in-the-middle phishing, cookie theft, and other used attacks. Last year I blogged about several modern...

Jeffrey Appel - Microsoft Security blog