Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

Source: The Hacker News

A threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to enroll a new Entra passkey with an aim to carry out data extortion attacks.

The threat actor, tracked by Okta under the moniker O-UNC-066, has deploye


Read original