16
Hundreds of orgs compromised daily in Microsoft device code phishing attacks
(www.theregister.com)
Cyber Security news and links to cyber security stories that could make you go hmmm. The content is exactly as it is consumed through RSS feeds and wont be edited (except for the occasional encoding errors).
This community is automagically fed by an instance of Dittybopper.
This has been happening to me the past few weeks, so I tried turning off app notification sign-in, and the attacker switched to entering passwords until it locked my account.
The only way to unlock it is to reset the password, and MS won't let me keep my old one ... why can't I use the old one again, especially if I recently changed it already?! The attackers clearly don't know it, but now they can make me go through the effort of setting a new password every day until I enabled app notification login again.
And then they just switched back to MFA phishing again. The attacker has even stopped bothering making the login request look like it's coming from the same country I live in.