Vue lecture

Il y a de nouveaux articles disponibles, cliquez pour rafraîchir la page.

Kali365 turns Microsoft device-code logins into persistent M365 access

Kali365 turns Microsoft device-code logins into persistent M365 access
Kali365 is targeting US organizations by abusing Microsoft’s legitimate device-code authentication flow, allowing attackers to obtain Microsoft 365 OAuth tokens without stealing passwords. More than 80 public sandbox sessions tied to the phishing kit are appearing each week, highlighting a persistent threat to corporate email, documents, and cloud services.

Source

Edit on-prem Exchange attributes in Exchange Online with writeback for cloud-managed remote mailboxes

Cloud-managed Exchange attribute architecture (image Microsoft)
Microsoft has made Exchange attribute writeback for cloud-managed remote mailboxes generally available. It lets you manage selected Exchange mailbox attributes in Exchange Online while copying a limited set of those values back to on-premises Active Directory through Microsoft Entra Cloud Sync. This article explains the prerequisites, configuration, verification, and operational limits for a hybrid Exchange organization.

Source

Using external fingerprint readers with Windows Hello Enhanced Sign-in Security

Confirm Enhanced Sign-in Security is on (image Microsoft)
Windows Hello Enhanced Sign-in Security (ESS) can now use a compatible external fingerprint reader for Windows sign-in on Windows 11, version 24H2 and 25H2. ESS is a Windows Hello protection mode that isolates biometric processing and the connection to the reader from the main operating system. This article explains the hardware and update requirements, enrollment process, verification steps, and deployment limits for Windows administrators.

Source

Malware can silently hijack Chrome’s synced passkeys on Windows

Malware can silently hijack Chrome’s synced passkeys on Windows
Malware with ordinary user privileges can bypass the protections users expect from Google Password Manager passkeys, including fingerprints, PINs, and visible prompts. Unit 42 identified three attack paths against Chrome’s Google Cloud Authenticator that can produce valid login assertions or extract synced passkey keys without breaking passkey cryptography.

Source

❌