1
0
1
0
1
0
1
0
0
1
1
0
1
0
VulnHub

AI-Powered Cybersecurity Intelligence

Attackers Use Fake OAuth Apps with Tycoon Kit to Breach Microsoft 365 Accounts

Source: The Hacker News | Added:

Cybersecurity researchers have reported that threat actors are using fake Microsoft OAuth applications to impersonate legitimate enterprises, enabling them to harvest credentials and execute account takeover attacks. These fraudulent applications mimic well-known companies such as RingCentral, SharePoint, Adobe, and Docusign.


Impact: RingCentral, SharePoint, Adobe, Docusign

In the Wild: Yes

Age: Newly disclosed

Remediation: Not specified

Microsoft
Read Full Original Article →