FreshRSS

๐Ÿ”’
โ˜ โ˜† โœ‡ The Hacker News

Hackers Using Malicious OAuth Apps to Take Over Email Servers

By Ravie Lakshmanan โ€” September 23rd 2022 at 05:14
Microsoft on Thursday warned of a consumer-facing attack that made use of rogue OAuth applications deployed on compromised cloud tenants to ultimately seize control of Exchange servers and spread spam. "The threat actor launched credential stuffing attacks against high-risk accounts that didn't have multi-factor authentication (MFA) enabled and leveraged the unsecured administrator accounts to
โŒ